Skip to main content

folkfox

Skip to main content
Skip to content
Threat Landscape

Nobody Exploited a Single Flaw. They Just Used the Password

No zero-day, no exploit chain, no clever bypass. A threat actor calling itself TheHatman walked into eight Fortune 500 tenants on stolen credentials alone, and the marketing lesson for security vendors is sharper than the technical one.

Quick answerManaged detection and response catches what perimeter tools miss: credentials already inside the system. TheHatman used no exploit, only stolen logins, to pull 3.64 million records from Azure and Entra ID tenants at eight named Fortune 500 firms.

Audio version

Listen to this article. The full text is below.

10 min · narrated · download

Section 01

What TheHatman actually did#

A fox on the prowl does not dig under the fence when the gate was left ajar in the hedgerow. That is the whole story of the campaign a threat actor calling itself TheHatman ran through August, and it is worth sitting with the plainness of it before reaching for anything more dramatic.

SecurityWeek reported on 17 August 2026 that stolen credentials, not a platform vulnerability, were used to exfiltrate employee directory data from at least eight Fortune 500 companies through their Microsoft Azure and Entra ID tenants. McDonald's, Vodafone, TCS and IHG were named among the victims. The primary writeup from Hudson Rock, the threat intelligence firm that first documented the campaign, is explicit about cause: this pattern points to targeted exploitation of infostealer infections, meaning credentials harvested from already-compromised employee devices, rather than any flaw in Microsoft's platform itself. Only Fortune 500 tenants were hit, which the firm reads as evidence the attacker was hunting valuable credential sets, not scanning blindly for a vulnerable configuration.

@IntCyberDigest
A threat actor using the alias "TheHatman" is selling 3.64 million employee records allegedly pulled from the Microsoft Entra/Azure tenants of McDonald's, Vodafone, TCS, HCL, IHG, Kyndryl and Gap using compromised credentials. Hudson Rock rates the samples as authentic, including service accounts and global administrator names.
17 August 2026View on X

TCS and Gap have denied any breach, according to BleepingComputer's own reporting on the listing. That denial matters and should be stated plainly rather than glossed over: a listing being offered for sale is a claim, and Hudson Rock's authenticity rating applies to the samples it reviewed, not necessarily to every company named in the seller's own advertisement. What is not in dispute is the mechanism, and the mechanism is the actual lesson.

A quarry this size does not announce its scent trail in advance. Nobody at any of the eight named tenants saw a queue of failed logins or a brute-force pattern to flag, because there was nothing noisy to catch. One valid credential, used quietly, reads as an ordinary sign-in to almost every tool built to watch the den door rather than the traffic already inside it.

Section 02

Why this was never a zero-day story#

There is a real temptation, in security marketing, to reach for the most dramatic available frame. TheHatman's campaign resists that temptation on its own evidence: no exploit chain, no proof-of-concept, no CVE. Global administrator credentials, once stolen from an infected endpoint, needed nothing more sophisticated than a login screen.

As of this writing, no Microsoft security advisory or MSRC blog post acknowledges TheHatman's campaign by name, and that gap is itself worth stating honestly rather than implying a response that has not happened. This is not a platform failure Microsoft needs to patch. It is an identity hygiene failure that sat entirely on the customer side of the shared responsibility line, in the credentials employees typed into infected machines long before any Azure tenant was touched.

Implies a platform flaw that does not exist

A sophisticated new attack has exposed critical vulnerabilities in Microsoft's cloud infrastructure, putting every enterprise tenant at risk.

Names the real, cheaper failure

Credentials stolen from infected employee devices, including at least one global administrator account, gave an attacker direct access with no exploit required.

The second version is less exciting and more useful, because it points a buyer at the control that would actually have stopped this: catching the credential theft or its first live use, not hardening a platform that was never the weak point. That is the specific, narrow claim identity threat detection tooling can make honestly, and it is a stronger pitch than a vaguer one about advanced threats.

Microsoft's own Entra ID Protection documentation describes exactly this capability: sign-in risk detection for leaked credentials, anonymous IP use and impossible travel, feeding into automatic conditional access policies that can force a password reset or multi-factor challenge before real damage spreads. That capability exists inside the platform TheHatman walked through. Whether it was licensed, configured and actually watched at each of the eight named tenants is a separate question, and it is precisely the question a brush-clearing audit answers before the next credential goes missing rather than after.

Section 03

The numbers behind credential theft, measured properly#

Marketing around a single incident tends to overstate or understate the pattern depending on which way sells better that week. The Verizon 2026 Data Breach Investigations Report gives a genuinely measured answer instead. SecurityWeek's summary of the report, drawn from 31,000 incidents and over 22,000 confirmed breaches, found that vulnerability exploitation overtook credential abuse as the top initial access vector for the first time in the report's nineteen-year history: 31%, up from 20% the year before, against 13% for credential abuse as the specific entry point.

Read only that headline and identity threat detection looks like yesterday's problem. It is not. The same report found credential abuse implicated in 39% of breaches across the full attack chain, not just the entry point, and stolen credentials appear as the compromised data type in 28% of breaches overall. Vulnerabilities get you in the door more often now. Credentials still do most of the damage once someone is inside, which is exactly the shape of TheHatman's campaign: a stolen login, then a wide, quiet walk through Entra ID with no further exploit needed.

Credential abuse across the full breach, not just the front door
Waffle chart showing credential abuse present in 39 percent of confirmed breaches39% of confirmed breaches in the Verizon2026 DBIR involved credential abuse somewhere in the att
Vulnerability exploitation now leads as the entry vector, but credential abuse still shows up in nearly four in ten confirmed breaches overall.

This is the honest pitch for managed detection and response and for identity threat detection specifically: not that credential theft is the newest threat, but that it remains one of the most persistent ones, precisely because it needs no exploit and therefore trips no vulnerability scanner.

Section 04

How much one stolen login can move#

Scale is where TheHatman's campaign becomes genuinely instructive for anyone building a managed detection and response pitch, because the exposure was wildly uneven across the named companies, and that unevenness itself tells a story about where identity governance was weakest.

Employee records exposed per company, TheHatman campaign
McDonald's
~1.7m
TCS
~800k
Vodafone
~425k
HCL
~250k
IHG
~185k
Kyndryl
~170k
Gap
~80k
Hexaware
~20k
Wyndham
~9k
McDonald's alone accounts for roughly as many exposed records as the other eight named companies combined, a gap that points to how differently each tenant had segmented and monitored its own directory.
fox examining a single stolen key among many, symbolising managed detection and response
One login. Nine companies. A very uneven spread.

A gap that wide, roughly 189 times between the largest and smallest figure Hudson Rock reported, is not explained by attacker effort alone. It reflects how much of each company's directory a single compromised account could actually reach before anything noticed. That is the specific, measurable thing managed detection and response providers sell: not the absence of a stolen credential, which is very hard to guarantee, but a hard ceiling on how far that one credential can travel before detection catches it.

Section 05

What managed detection and response providers should actually say#

The natural marketing move after a story like this is to lead with fear. The more durable move is to lead with the specific, narrow claim the incident actually supports, then let the buyer draw their own conclusion about scale.

Five claims TheHatman's campaign actually supports
Name the real vector

State plainly that this was credential theft, not a platform exploit. Overclaiming a zero-day where none exists is checkable and will cost credibility.

Lead with containment, not prevention

No vendor can promise zero stolen credentials. Managed detection and response's honest pitch is limiting what one stolen login can reach.

Cite the DBIR figure precisely

39% of breaches involving credential abuse across the attack chain is a stronger, more durable claim than any single incident's headline number.

Show the exposure spread, not just the total

The 189-to-1 gap between McDonald's and Wyndham's exposure is more persuasive than an aggregate figure, because it shows detection speed, not just presence, decides the damage.

Answer the MSSP-versus-MDR question directly

Buyers researching this incident will search exactly that comparison. A page that answers it plainly earns the click a vaguer one loses.

Three terms buyers researching this incident will search, answered in one place rather than scattered across a vendor's site.
TermWhat it actually isWhat it would have caught here
MSSPOutsourced monitoring of existing security tools, largely reactiveOnly if the outsourced team was actively watching Entra ID sign-in logs
SIEMA log aggregation and alerting platform, needs active tuning and staffingOnly with rules built specifically for anomalous sign-ins and directory reads
Managed detection and responseActive, staffed threat hunting across identity, endpoint and cloud signalsDirectly, if credential-based anomalies were in scope from day one

That table is the answer to what is the difference between mssp and mdr, and it is worth publishing in exactly that plain form, because the honest answer sells the category better than a longer, vaguer one would.

Section 06

Building an identity threat detection response that survives a login-only breach#

The uncomfortable truth in TheHatman's campaign is that no perimeter control was ever going to stop it, because there was no perimeter to breach. The response has to sit at the identity layer itself.

A practical identity threat detection programme, built for this exact failure mode rather than a generic checklist, runs on continuous sign-in anomaly detection, tight monitoring of global administrator accounts specifically, and a genuine incident response plan for when, not if, a credential shows up for sale somewhere Hudson Rock or a similar firm is watching.

None of this needs exotic tooling to start. NIST's Digital Identity Guidelines, SP 800-63B, set out the baseline for credential strength, verifier throttling and compromised-password checks that a login-only breach like this one exploits when it is missing. The UK's National Cyber Security Centre's password guidance and the Cybersecurity and Infrastructure Security Agency's own advice converge on the same blunt point: require multi-factor authentication everywhere a credential alone currently grants access, because a stolen password with no second factor is exactly the undergrowth TheHatman moved through unnoticed.

The cheapest attack in the whole toolkit is still someone else's password. Managed detection and response earns its fee by shortening the distance that password can travel.
folkfox, on the TheHatman credential theft campaign

For vendors and marketing teams in this space, the pitch writes itself once the framing is honest: not a promise that no credential will ever be stolen, which nobody can make, but a measurable claim about how fast the theft is caught and how far it is allowed to travel before it is.

A vulpine security posture does not try to outrun every threat on the open field. It learns the trail the last one took and closes it before the next one arrives, which is a calmer, more durable pitch than a moonlit chase after the fact. TheHatman will not be the last actor to find a login sitting in the open, and the vendors who win the next twelve months of this conversation will be the ones who can name, in plain language, exactly how much shorter that trail now is.

Questions

Frequently asked questions#

What is managed detection and response?

Managed detection and response is an outsourced service that actively hunts for threats across a company's endpoints, cloud tenants and identity systems, rather than passively collecting alerts. It differs from a traditional MSSP by combining active threat hunting with a defined response, not just monitoring.

What is the difference between MSSP and MDR?

An MSSP typically monitors existing security tools and alerts a customer's team to act. Managed detection and response goes further: a staffed team actively hunts for and responds to threats directly, including identity-based attacks like stolen credentials.

What is a SIEM vs MDR?

A SIEM is a log aggregation and alerting platform that needs a team to build rules and respond to alerts. Managed detection and response is the staffed service that does that active hunting and response, sometimes using a SIEM as one of its data sources.

How did TheHatman access Fortune 500 Azure tenants without an exploit?

Stolen credentials, likely harvested from infostealer malware on already-infected employee devices, were used to log in directly. No vulnerability in Microsoft's Azure or Entra ID platform was involved, according to Hudson Rock's analysis.

Is credential theft still a major cause of data breaches?

Yes. The Verizon 2026 Data Breach Investigations Report found credential abuse implicated in 39% of confirmed breaches across the full attack chain, even though vulnerability exploitation has overtaken it as the single most common entry point.

What is identity threat detection?

Identity threat detection is the practice of monitoring sign-ins, privilege changes and directory activity for signs of a compromised account, rather than relying only on perimeter or endpoint tools that a stolen credential can simply bypass.

Keep reading

Read more on this topic#

Ready to market detection, not just prevention?

folkfox builds the content and keyword strategy for MDR, identity security and MSSP vendors who want an honest, checkable pitch, not a fear-led one.