Hacker Claims 3.6 Million Azure Records Stolen From McDonald’s, Vodafone and Others

A hacker claims to be selling 3.6 million Azure-linked employee records from McDonald’s, Vodafone, TCS, and others, but no breach is confirmed.

Aug 18, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A cybercriminal using the handle “TheHatman” claims to be selling more than 3.6 million employee-directory records obtained from the Microsoft Entra ID environments of major companies including McDonald’s, Vodafone, and Tata Consultancy Services.

The seller began advertising the stolen databases across cybercrime forums including DarkForum, PwnForums, and BreachForumsSt between July 31 and mid-August.

The largest individual dataset claims to expose over 1.7 million records from McDonald’s Corporation, advertised as an “internal employee dump downloaded directly from Azure Tenant using compromised credentials.”

“TheHatman” advertises alleged employee data on a cybercrime forum. Credit: Hudson Rock

Other prominent enterprise listings include:

  • Tata Consultancy Services (TCS): ~800,000 records
  • Vodafone: ~425,000 records
  • HCL Technologies: ~250,000 records
  • InterContinental Hotels Group (IHG): ~185,000 records
  • Kyndryl: ~170,000 records
  • Gap Inc.: ~80,000 records
  • Hexaware Technologies: ~20,000 records
  • Wyndham Hotels: ~9,000 records

The datasets consist of core enterprise directory attributes: full names, employee IDs, phone numbers, postal addresses, corporate email addresses (including native .onmicrosoft.com routing), job titles, manager assignments, group memberships, and lists of service accounts and Global Administrators.

Targeted theft over platform flaws

Threat intelligence firm Hudson Rock assessed samples of the advertised data as “highly likely authentic,” citing corporate email structures and fields consistent with Microsoft Entra ID directory exports. However, the datasets’ provenance, age, and method of extraction have not been independently confirmed.

“The exposure of service accounts and global admin names is particularly concerning, as this provides a direct roadmap for subsequent social engineering, spear-phishing, or targeted privilege escalation attacks against these organizations,” Hudson Rock noted.

Rather than a zero-day flaw in Azure itself, security analysts attribute the breaches to infostealer malware, which pilfers saved browser passwords and session tokens from infected employee computers. Hudson Rock identified compromised credentials originating from infostealer logs tied to several affected companies, including TCS, Gap, HCL Technologies, and Kyndryl.

Advertisement

According to BleepingComputer, both TCS and Gap have pushed back on claims of a recent network breach. TCS informed the National Stock Exchange of India that its review found no credible evidence of an intrusion, adding that the data appears to be more than four years old. A Gap spokesperson similarly stated that preliminary reviews showed no corporate systems were compromised and that the advertised data was non-sensitive and dated.

“TheHatman” advertises alleged employee data on a cybercrime forum. Credit: HudsonRock.

The real risk is what comes next

Even if some of the records are old, detailed employee directories can become valuable attack material. Knowing an employee’s manager, job title, phone number and corporate email address gives criminals enough context to make phishing or impersonation attempts appear credible.

The exposure of administrator and service-account information raises the stakes further because it can help attackers prioritize accounts that could provide deeper access. For companies, the incident underscores a shift in cloud security: protecting passwords alone is no longer enough. Organizations also need to watch for stolen session tokens and infostealer infections, limit directory visibility and tightly control applications with access to Entra environments.

For employees, unexpected calls or messages that already know their job title, manager or workplace details deserve extra scrutiny.

Read more: Learn how attackers are moving beyond password theft to target Microsoft authentication flows and session tokens in Phishing Tactics Target Session Tokens and Deliver Malware.

AA

Aminu Abdullahi is an experienced B2B technology and finance writer. He has written for various publications, including TechRepublic, eWEEK, Enterprise Networking Planet, eSecurity Planet, CIO Insight, Enterprise Storage Forum, IT Business Edge, Webopedia, Software Pundit, Geekflare and more.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.