Skip to content
skopnix
← adversaries
Unknown

TheHatman

misp-galaxyrefreshed 2026-09-15

sigil

Last 30 days

last seen 29 d ago

1
dispatch
0
victims
0
CVEs seen
Analyst brief

TheHatman is a highly organized threat actor known for systematically listing and selling internal employee directories stolen from major corporations, including nine Fortune 500 enterprises across various sectors. The actor claims to have obtained the data through compromised credentials, though the initial entry point remains under investigation. The volume of data suggests that after gaining access, TheHatman employed automated scripts, likely utilizing PowerShell modules or Python libraries, to extract the directories in bulk.

On the wire
Take it with you
References
Early access

Track TheHatman on the wire.

Early access opens the actor API and MCP server first — and an alert every time this adversary lands on the wire. One email when it's ready.

bot-protected