TheHatman

Profile updated
2026-09-03 03:00:02

Context

TheHatman is a highly organized threat actor known for systematically listing and selling internal employee directories stolen from major corporations, including nine Fortune 500 enterprises across various sectors. The actor claims to have obtained the data through compromised credentials, though the initial entry point remains under investigation. The volume of data suggests that after gaining access, TheHatman employed automated scripts, likely utilizing PowerShell modules or Python libraries, to extract the directories in bulk.

Reports & references

  • thecybersecguru.com — Azure Data Exfiltration Thehatman Campaign (report)

External references