A hacker claims to be selling 3.6 million Azure-linked employee records from McDonald’s, Vodafone, TCS, and others, but no breach is confirmed.
The post Hacker Claims 3.6 Million Azure Records Stolen From McDonald’s, Vodafone and Others appeared first on eSecurity Planet.
A hacker claims to be selling 3.6 million Azure-linked employee records from McDonald’s, Vodafone, TCS, and others, but no breach is confirmed.
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More
A cybercriminal using the handle “TheHatman” claims to be selling more than 3.6 million employee-directory records obtained from the Microsoft Entra ID environments of major companies including McDonald’s, Vodafone, and Tata Consultancy Services.
The seller began advertising the stolen databases across cybercrime forums including DarkForum, PwnForums, and BreachForumsSt between July 31 and mid-August.
The largest individual dataset claims to expose over 1.7 million records from McDonald’s Corporation, advertised as an “internal employee dump downloaded directly from Azure Tenant using compromised credentials.”
“TheHatman” advertises alleged employee data on a cybercrime forum. Credit: Hudson Rock
Other prominent enterprise listings include:
The datasets consist of core enterprise directory attributes: full names, employee IDs, phone numbers, postal addresses, corporate email addresses (including native .onmicrosoft.com routing), job titles, manager assignments, group memberships, and lists of service accounts and Global Administrators.
Targeted theft over platform flawsThreat intelligence firm Hudson Rock assessed samples of the advertised data as “highly likely authentic,” citing corporate email structures and fields consistent with Microsoft Entra ID directory exports. However, the datasets’ provenance, age, and method of extraction have not been independently confirmed.
“The exposure of service accounts and global admin names is particularly concerning, as this provides a direct roadmap for subsequent social engineering, spear-phishing, or targeted privilege escalation attacks against these organizations,” Hudson Rock noted.
Rather than a zero-day flaw in Azure itself, security analysts attribute the breaches to infostealer malware, which pilfers saved browser passwords and session tokens from infected employee computers. Hudson Rock identified compromised credentials originating from infostealer logs tied to several affected companies, including TCS, Gap, HCL Technologies, and Kyndryl.
According to BleepingComputer, both TCS and Gap have pushed back on claims of a recent network breach. TCS informed the National Stock Exchange of India that its review found no credible evidence of an intrusion, adding that the data appears to be more than four years old. A Gap spokesperson similarly stated that preliminary reviews showed no corporate systems were compromised and that the advertised data was non-sensitive and dated.
“TheHatman” advertises alleged employee data on a cybercrime forum. Credit: HudsonRock.
The real risk is what comes next
Even if some of the records are old, detailed employee directories can become valuable attack material. Knowing an employee’s manager, job title, phone number and corporate email address gives criminals enough context to make phishing or impersonation attempts appear credible.
The exposure of administrator and service-account information raises the stakes further because it can help attackers prioritize accounts that could provide deeper access. For companies, the incident underscores a shift in cloud security: protecting passwords alone is no longer enough. Organizations also need to watch for stolen session tokens and infostealer infections, limit directory visibility and tightly control applications with access to Entra environments.
For employees, unexpected calls or messages that already know their job title, manager or workplace details deserve extra scrutiny.
Read more: Learn how attackers are moving beyond password theft to target Microsoft authentication flows and session tokens in Phishing Tactics Target Session Tokens and Deliver Malware.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Microsoft Links More Than 30 Domains to MacSync Stealer | 0 | 10.46 | 19-08-2026 |
| 2 | Hackers exploit macOS Screen Sharing flaw to deploy Monero miner | 0 | 8.31 | 14-08-2026 |
| 3 | T-Mobile Cuts Network Cable to Stop Salt Typhoon Hackers | 0 | 8.52 | 20-08-2026 |
| 4 | AFP: компания Airbus стала жертвой кибератак | 0 | 0 | 26-09-2019 |
| 5 | Open House: How an Unauthenticated MCP Server Exposed India's Largest Real Estate Platform | UpGuard | 0 | 5.85 | 21-07-2026 |
| 6 | Data of 15 Million Kazakhstanis Allegedly Leaked | 0 | 11.26 | 12-08-2026 |
| 7 | Microsoft Links Hotel Wi-Fi Attacks Stealing Microsoft 365 Accounts to Russian Hackers | 0 | 11.88 | 06-08-2026 |
| 8 | RingCentral data breach exposed info of 1.6 million accounts | 0 | 10.39 | 14-08-2026 |
| 9 | Хакеры украли данные 37 млн абонентов сотового оператора T-Mobile в США | 0 | 0 | 20-01-2023 |