Unknown
TheHatman
misp-galaxyrefreshed 2026-09-15
sigil
Last 30 days
last seen 29 d ago
1
dispatch
0
victims
0
CVEs seen
Analyst brief
TheHatman is a highly organized threat actor known for systematically listing and selling internal employee directories stolen from major corporations, including nine Fortune 500 enterprises across various sectors. The actor claims to have obtained the data through compromised credentials, though the initial entry point remains under investigation. The volume of data suggests that after gaining access, TheHatman employed automated scripts, likely utilizing PowerShell modules or Python libraries, to extract the directories in bulk.
Early access
Track TheHatman on the wire.
Early access opens the actor API and MCP server first — and an alert every time this adversary lands on the wire. One email when it's ready.
bot-protected