TheHatman
MISP
Type:
Unknown
Unknown
Country:
Unknown
Unknown
First seen:
Unknown
Unknown
Details:
TheHatman is a highly organized threat actor known for systematically listing and selling internal employee directories stolen from major corporations, including nine Fortune 500 enterprises across various sectors. The actor claims to have obtained the data through compromised credentials, though the initial entry point remains under investigation. The volume of data suggests that after gaining access, TheHatman employed automated scripts, likely utilizing PowerShell modules or Python libraries, to extract the directories in bulk.
Metadata
| ID: | 1121 |
| Created: | 02/09/2026 16:00 |
| Updated: | 11/09/2026 04:00 |