Hacker Sells Millions of Employee Records from McDonald’s, Vodafone, and Other Major Companies

18.08.2026 3 minutes Author: Newsman

McDonald’s, Vodafone, and Other Major Companies Targeted in Azure Credential Theft Campaign.

The attacker has flooded underground forums with datasets offered for sale. According to the hacker, the information was stolen from the Microsoft Azure and Entra cloud environments of some of the world’s largest companies. The data could potentially help cybercriminals carry out targeted attacks against employees.

The threat actor, who goes by the alias TheHatman, has posted data linked to at least nine major companies on underground forums over the past week.

  • McDonald’s Corporation: 1,700,000 records

  • Tata Consultancy Services (TCS): 800,000 records

  • Vodafone: 425,000 records

  • HCL Technologies: 250,000 records

  • InterContinental Hotels Group (IHG): 185,000 records

  • Kyndryl: 170,000 records

  • Gap Inc.: 80,000 records

  • Hexaware Technologies: 20,000 records

  • Wyndham Hotels: 9,000 records

To support his claims, the threat actor published samples of the data. Although the link to download the McDonald’s data sample was not working at the time it was checked, records from other companies provided insight into the type of information that may have been included in the allegedly stolen datasets.

The published samples contained employees’ corporate email addresses, phone numbers, job titles, full names, and workplace addresses. The companies potentially affected by the incident have been contacted for comment. The article may be updated once responses are received.

Companies and Employees Face the Risk of Social Engineering Attacks

“For individuals, this means an increased risk of social engineering attacks. The compromised credentials may have already been changed, but if not, they could be used to facilitate further data theft,” the researchers noted.

With accurate information about employees, executives, departments, and reporting structures within a company, attackers can craft highly convincing phishing messages.

For example, a cybercriminal could impersonate an employee’s manager or an IT administrator and use real corporate information to make the request appear legitimate.

Attackers May Have Used Infostealers

The records appear to match the structure of an Azure directory export. However, the exact method the attackers may have used to gain access to the companies’ systems remains unclear. TheHatman claims the information was obtained using compromised credentials.

Cybersecurity company Hudson Rock said it found evidence linking infostealer infections to compromised Azure credentials associated with several companies, including TCS, Gap, HCL Technologies, and Kyndryl.

Infostealers are malicious programs designed to steal information from infected computers, including passwords, browser data, and active session cookies. In some cases, stolen session data can allow attackers to access online services without having to re-enter the victim’s password.

“Given the enormous scale of the affected organizations, it is highly likely that this campaign resulted from the targeted exploitation of infostealer infections rather than a systemic zero-day vulnerability in Azure,” Hudson Rock said.

“If this were a widespread vulnerability, we would likely see a much broader range of affected organizations, including small businesses, rather than only large Fortune 500-level enterprises,” the company added.

Subscribe
Notify of
0 Коментарі
Oldest
Newest Most Voted
Found an error?
If you find an error, take a screenshot and send it to the bot.