← BACK TO FEED
Azuredata breachinfostealerFortune 500credential theft

Hacker Flogs Azure Directory Data From McDonald's, Vodafone and a Stack of Fortune 500 Names

A threat actor known as 'TheHatman' is selling data allegedly stolen from the Azure tenants of multiple Fortune 500 companies, including McDonald's, TCS, Vodafone, and Wyndham Hotels, with the McDonald's dataset alone containing over 1.7 million records. The data, which appears to have been exfiltrated using leaked credentials from a targeted infostealer campaign, includes sensitive employee information such as names, email addresses, job titles, and privileged account details. Security firm Hudson Rock warns the breach poses a serious risk, as the exposed data could enable attackers to conduct spear-phishing, business email compromise, and privilege escalation attacks against the affected organisations.

A threat actor going by 'TheHatman' is selling what appears to be internal employee directory data lifted from the Azure tenants of some very recognisable companies. The alleged victims include McDonald's, Tata Consultancy Services, Vodafone, HCL Technologies, InterContinental Hotels Group, Kyndryl, Gap Inc., Hexaware Technologies, and Wyndham Hotels.

The method, according to the attacker, was straightforward: leaked credentials used to access Azure and Entra instances directly. No exotic zero-days, just someone else's login details doing the heavy lifting.

Cybersecurity firm Hudson Rock took a look at the data and concluded it looks genuine. The email addresses and field structures match what you'd expect from Azure directory exports, which isn't a great sign for the companies involved.

The McDonald's dataset is the biggest of the lot, clocking in at over 1.7 million records. TCS comes in second at 800,000, Vodafone at 425,000, HCL Technologies at 250,000, and IHG at 185,000. Across all of them, the stolen fields follow a consistent pattern: names, corporate emails, phone numbers, physical addresses, employee IDs, job titles, manager relationships, and group memberships.

The bit that should genuinely worry security teams is the inclusion of service account details and global admin usernames. That kind of information hands attackers a ready-made map for privilege escalation, targeted phishing, or business email compromise campaigns. It's not just embarrassing data to have floating around a forum, it's operationally useful to anyone planning a follow-on attack.

Hudson Rock believes the initial access came via infostealer malware. The firm found compromised credentials tied to most of the affected organisations, and the targeting pattern, spanning IT services, hospitality, telecoms, retail, and logistics, suggests this wasn't opportunistic. Someone went looking for specific tenants.

None of the named companies have publicly confirmed a breach at the time of writing.

READ NEXT
French Tax Authority Breach Exposes Financial Data on 680,000 CitizensSnowflake Breach Hacker Pleads Guilty: 100 Million Records, Stale Passwords, and No MFAACR Stealer Is Raiding Enterprise Networks and All It Needs Is for Someone to Press Enter