The attacker has flooded underground forums with datasets offered for sale. According to the hacker, the information was stolen from the Microsoft Azure and Entra cloud environments of some of the world’s largest companies. The data could potentially help cybercriminals carry out targeted attacks against employees.
The threat actor, who goes by the alias TheHatman, has posted data linked to at least nine major companies on underground forums over the past week.
McDonald’s Corporation: 1,700,000 records
Tata Consultancy Services (TCS): 800,000 records
Vodafone: 425,000 records
HCL Technologies: 250,000 records
InterContinental Hotels Group (IHG): 185,000 records
Kyndryl: 170,000 records
Gap Inc.: 80,000 records
Hexaware Technologies: 20,000 records
Wyndham Hotels: 9,000 records
To support his claims, the threat actor published samples of the data. Although the link to download the McDonald’s data sample was not working at the time it was checked, records from other companies provided insight into the type of information that may have been included in the allegedly stolen datasets.
The published samples contained employees’ corporate email addresses, phone numbers, job titles, full names, and workplace addresses. The companies potentially affected by the incident have been contacted for comment. The article may be updated once responses are received.

“For individuals, this means an increased risk of social engineering attacks. The compromised credentials may have already been changed, but if not, they could be used to facilitate further data theft,” the researchers noted.
With accurate information about employees, executives, departments, and reporting structures within a company, attackers can craft highly convincing phishing messages.
For example, a cybercriminal could impersonate an employee’s manager or an IT administrator and use real corporate information to make the request appear legitimate.
The records appear to match the structure of an Azure directory export. However, the exact method the attackers may have used to gain access to the companies’ systems remains unclear. TheHatman claims the information was obtained using compromised credentials.
Cybersecurity company Hudson Rock said it found evidence linking infostealer infections to compromised Azure credentials associated with several companies, including TCS, Gap, HCL Technologies, and Kyndryl.
Infostealers are malicious programs designed to steal information from infected computers, including passwords, browser data, and active session cookies. In some cases, stolen session data can allow attackers to access online services without having to re-enter the victim’s password.
“Given the enormous scale of the affected organizations, it is highly likely that this campaign resulted from the targeted exploitation of infostealer infections rather than a systemic zero-day vulnerability in Azure,” Hudson Rock said.
“If this were a widespread vulnerability, we would likely see a much broader range of affected organizations, including small businesses, rather than only large Fortune 500-level enterprises,” the company added.