5 Million Records, One Login: TheHatman's Entra ID Harvest Exposes McDonald's, TCS, Vodafone

5 Million Records, One Login: TheHatman's Entra ID Harvest Exposes McDonald's, TCS, Vodafone

TL;DR

  • 5 Million Records Later: TheHatman Exploits Entra ID's Default Permissions — No Zero-Day Required. Is your company's employee directory already for sale on the dark web?
  • $1M Escrow Punching Bag: US Authorizes Private Cyber-Warfare Firms Under New Order. Who gets sued first when a private cyber-SWAT hits US infrastructure?
  • VMware Memory-Corruption Bug Bricks Apple Hosts: Broadcom's Trust Crisis Deepens. Still betting your 5G core on VMware after two critical vulns in a month?

😏 Oh Good, Your Boss's Email Is Now a Dark-Web Freebie

5 million employee records — McDonald's, TCS, Vodafone, HCLTech — all leaked by one guy who just
 logged in. No zero-day, no exploit, no nation-state. Just an infostealer on a managed laptop and Microsoft's Directory.Read.All scope working exactly as designed 😏 Social engineering goldmine: name + role + boss + location handed to criminals on a silver API. Your security team burned hours chasing dark-web uploads while the actual infostealer sat untouched on someone's machine. The fix costs $0. Restrict Graph API permissions. Enforce FIDO2. Scan your endpoints. Or keep paying TheHatman's subscription fee — your call. How many of your employees' records are already on the menu?

Here's the thing about Microsoft Entra ID (formerly Azure AD, formerly "we swear it's secure this time"): a single infostealer on a managed laptop, and a bored guy in a hoodie grabs every employee's work email, office address, job title, and reporting chain without a single alert. TheHatman has been doing exactly that since early August.

The Mechanics of Pain

  • August 9, 2026: TheHatman posts ~250,000 HCLTech employee records for sale. Not hacked. Not exploited. Just
 exported. Compromised Entra credentials with Directory.Read.All scope—harvested from an infostealer-infected endpoint—made it trivial.
  • August 10–12: He floods cybercrime forums with enterprise employee database downloads. McDonald's: 1.7 million records. TCS: ~800,000. Vodafone: 425,000. HCLTech: 250,000. IHG: 185,000. Kyndryl: 170,000. Gap Inc.: 80,000. Hexaware: 20,000. Wyndham: 9,000. Over 5 million records total.
  • August 12: Multiple Fortune 500 firms confirm unauthorized bulk exports of internal directories. TheHatman didn't break in. He logged in.

The exploit path is embarrassingly simple: infostealer malware on a managed device → credential theft → silent iteration across millions of records using default Microsoft Graph API permissions. No MFA bypass, no zero-day, no nation-state actor. Just a guy who read the Entra documentation better than your security team.

What This Actually Means

  • Social engineering surface area: Name + role + location + hierarchy = phishing emails your own employees will trust, enabling direct Business Email Compromise campaigns.
  • Global admin targeting: Service accounts and Global Administrator names dumped in the leak enable credential-stuffing attempts against privileged users and direct lateral movement.
  • False confidence tax: Victim teams burn hours chasing dark-archive uploads while the real infection—the infostealer on someone's laptop—sits untouched. Waste of time, but hey, billable hours.
  • Subscription model: Leaked records double as advertising. "Want fresher data? Pay me monthly."

The Punchline

India's largest IT firms—TCS, HCLTech, InterContinental Hotels Group—all confirmed unauthorized directory exports. TCS denies a breach but admits data appears to be legitimate directory exports, with no evidence of mass compromise. Microsoft's response? "Default permissions working as designed." Meanwhile, on August 11, a threat actor started shopping an unconfirmed 800,000-record TCS dataset—same playbook, just louder. TheHatman didn't invent a new attack; he just found the API endpoint your compliance team forgot to restrict.

The Outlook

Similar credential-harvesting patterns will persist as long as organizations treat Entra ID's default Directory.Read.All scope as a suggestion rather than a liability. The fix costs $0: restrict Graph API permissions, monitor service principal usage, enforce FIDO2 auth and token protection, and maybe—just maybe—scan your endpoints for the malware that's been running since August.

Or keep paying the subscription fee. Your call. 😏


🎯 Private Sector Cyber-SWAT: Uncle Sam's New $1M Escrow Punching Bag

$1M escrow bond and you get to punch foreign botnets in the face. 🎯 Uncle Sam just authorized private firms to destroy data and disrupt cybercrime sources—because the feds couldn't fill 25K cyber roles and China's got ten times the workforce. The Pentagon's "civilian harm assessment" got replaced by a Palantir black box. Ukraine's June toll hit 293 killed. Congress threw $63M at CyberCorps to unf*ck the brain drain. So the same government that warned about private-sector overreach now hands them the keys to offensive ops—with a million-dollar leash. Who actually gets sued first when a failsafe hits a US water plant?

So the US government finally realized its own cyber-defense is held together with bubblegum and expired CAC cards, and decided to outsource the beating. On August 12, 2026, Trump signed a National Security Presidential Memorandum creating the first US program that explicitly authorizes private firms to conduct offensive cyber operations—including data-destroying systems—against foreign cybercrime sources. Three months after his March 6th election victory and his very next-day "Combating Cybercrime" executive order. Because nothing says "coordinated strategy" like a midnight signature and a panic-room organizational chart.

How the rigged game works:

  • Private firms deploy offensive AI-driven countermeasures against active threats targeting federal infrastructure. OpenAI's Daybreak platform already demonstrated the blueprint—its Red-tier agents found two zero-days in Google's V8 engine by August 10, and scored high at CyberGym benchmarks. Automation handles the tedious bits.
  • A $1-million escrow bond per company sits as collateral under DOJ and DHS joint oversight. Thomas Lind's advisory office confirmed no authorization planned for every action—the mechanism is government approval plus written permission, and any unauthorized hit on US systems forfeits participation. Think of it as a performance bond crossed with a "don't get cute" leash.
  • Vetted firms posting bonds fund surveillance and disruption missions directed exclusively through Executive Directors. Companies incur single liability if rules break. Potential collateral damage if failsafe actions trigger—especially impacting energy and water infrastructure domains where risk is life-endangering.

The damage (prevented):

The Pentagon's own civilian-harm assessment teams got gutted in July, leaving CENTCOM with exactly one assessor and the rest replaced by a Palantir black box marketed as "safety." Meanwhile, Ukraine's June civilian casualty count hit 293 killed and 1,990 injured—the highest since April 2022—driven by long-range rockets and drones hitting Kyiv and Dnipro. Congress intervened on June 12 to appropriate $63 million keeping CyberCorps running after administration cuts, with new AI-education requirements for participants. The program addresses the 25,000 unfilled federal cyber roles as China's running a tenfold workforce advantage and the FBI's bleeding staff.

Twenty raised $100M at a $1B valuation on June 17—America's first VC-backed cyber warfare startup, building AI offensive systems to protect global democracies. The math writes itself: contract out the punch, hold a million bucks hostage.

What's next:

  • Q4 2026: EU partner integration begins via NIS2 directive mandates. Program scaling continues. Expect more "private sector innovation" serving federal interests.
  • Six-month outlook: Coordinated center setup with classified annex approvals and commercial partnerships, per the August 12 memorandum.

The irony? The same government that spent decades warning about private sector overreach just handed them the keys to federal cyber operations—with a $1M charm bracelet to keep them honest. Hack the system, don't get hacked by it. 🎯


💀 Another Brick in the VMware Wall

$50K coaster or 5G outage? VMware's vmwkernel memory-corruption bug (disclosed Aug 18) turns Apple-based hosts into unresponsive bricks on any large file operation 💀 Zero recovery. No SSH. No ping. Just a $50K paperweight. Broadcom pushed a 9.8 CVSS auth bypass three weeks ago. Two critical vulns in a month. T-Mobile sued over license support. GEICO and HPE already jumped ship. Your "enterprise hypervisor" is a ticking time bomb—and September's patch won't fix the trust. Enjoy that change window. đŸ€Ą

Look, I get it. You spent a fortune on VMware licenses, convinced your CFO that "private cloud agility" was worth the premium, and now a single large file operation can turn your entire host into a screaming paperweight. Welcome to August 18, 2026—where Jacky Yang dropped the find of the week: a critical memory-corruption gremlin in vmwkernel that renders the whole host unresponsive on crash, with zero recovery baked in. đŸ€Ą

What Actually Happens

The bug triggers during large file operations on Apple hardware—specifically the cmrjack2.mac code path. Memory goes sideways, the kernel locks up, and your device becomes a $50,000 coaster. No SSH. No ping. No graceful shutdown. Just the quiet, existential dread of watching your failover cluster not fail over.

Impact breakdown:

  • Complete host loss: device becomes unreachable—lights-on, nobody-home state.
  • Extreme downtime: recovery means physical intervention or full node rebuild.
  • Apple-hardware specific: so your Mac mini clusters are ground zero for this particular flavor of pain.

The Timeline of "We'll Get to It"

  • Aug 18, 2026: Yang's disclosure hits—Cloud Foundation, Telco Cloud, vCenter stacks all affected.
  • Sept 2026 (promised): patch targeted, pending TML resolution. That's "The Management Layer" in VMware-speak, which is corporate for "we're still figuring out who broke what."

Why This Hurts

VMware owns the telco virtualization stack. Cloud Foundation is the spine of half the world's 5G core deployments. A memory corruption that nukes the entire hypervisor isn't a Tuesday patch—it's a mobile network outage, a data center incident ticket, and a cheerful email from legal about SLA breach penalties.

And this isn't VMware's first rodeo. July 29, 2026: Broadcom pushed emergency patches for a vCenter authentication bypass (CVE-2026-59309) scoring a cozy 9.8 CVSS—full system takeover via remote code execution. That's two critical vulns inside a month. The pattern is clear: your "enterprise-grade hypervisor" keeps demonstrating it dies harder than a $300 KVM.

Realpolitik take: Broadcom's licensing bloodbath is already gutting VMware shops. T-Mobile sued Broadcom on July 1, 2026 over expired perpetual license support—court ordered a $5.28M penalty to keep legacy VMs alive through August 3. Both GEICO and HPE signaled full migration: GEICO moved to OpenStack, cutting downtime 40%; HPE dangled free Morpheus and $1 Zerto credits as June 2026 escape hatches. Projections hit 33% of VMware workloads migrating by January 2028. Maybe that Proxmox trial isn't looking so ridiculous now, huh?

The Punchline

September's patch will fix the code. It won't fix the trust. Meanwhile, your hardware is a ticking bomb every time someone runs a big cp or dd command. Enjoy that 4-hour change window. 💀