Massive Azure data leak hits McDonald’s, Vodafone, and other global brands

A hacker claims to be selling employee datasets from numerous international companies, including McDonald’s, Vodafone, Kyndryl, InterContinental Hotels, and others.
A threat actor who operates under the moniker “TheHatman” has been flooding cybercrime forums on the dark web with internal employee directories belonging to several Fortune 500 companies across multiple sectors, such as IT services, hospitality, telecommunications, retail, and logistics.
The attacker claims these dumps were extracted directly from the organizations’ Azure Tenants.
Allegedly, he was able to extract over 1.7 million records from McDonald’s, 800,000 records from Tata Consultancy Services (TCS), 425,000 records from Vodafone, 250,000 records from HCL Technologies, 185,000 records from InterContinental Hotels Group (IHG), 170,000 records from Kyndryl, 80,000 records from Gap Inc., 20,000 records from Hexaware Technologies, and 9,000 records from Wyndham Hotels.
To prove his point, “TheHatman” uploaded sample data for each of his victims.
Researchers at Hudson Rock reviewed the sample datasets and concluded they appear legitimate, though the intrusion method hasn’t been independently confirmed.
Analysis shows that the threat actor managed to steal:
- Identity and contact information, including names, corporate email addresses, phone numbers, and physical addresses.
- Organizational structure data, including employee IDs, job titles, departments, notes, manager details, and direct reports.
- Access and group mappings information, including user group memberships, service accounts, and highly privileged account records, such as global administrator listings.
“The exposure of service accounts and global admin names is particularly concerning, as this provides a direct roadmap for subsequent social engineering, spear-phishing, or targeted privilege escalation attacks against these organizations,” Hudson Rock says about the severity of the breach.
The hacker claims that he used compromised credentials to extract the datasets, which seems to be correct.
Security researchers found compromised Azure credentials originating from Infostealer infections linked to most of the affected companies.
“The sheer scale and speed of these dumps suggest a systematic, automated approach once initial access is achieved,” Hudson Rock concludes.