HomeCyber AttacksHacker Claims Theft of Millions of Records from McDonald's, Vodafone and Other...

Hacker Claims Theft of Millions of Records from McDonald’s, Vodafone and Other Fortune 500 Azure Systems

A threat actor operating under the alias “TheHatman” is claiming to have stolen and is now selling millions of employee records taken directly from the Microsoft Azure and Entra directory systems of several Fortune 500 companies. The claims surfaced in reporting published on August 17, 2026, and point to one of the larger corporate data theft campaigns disclosed so far this year.

According to the reporting, the companies named as affected include McDonald’s Corporation, with more than 1.7 million records reportedly taken, Tata Consultancy Services with around 800,000 records, Vodafone with roughly 425,000 records, and HCL Technologies with about 250,000 records. InterContinental Hotels Group, Kyndryl, Gap Inc., Hexaware Technologies, and Wyndham Hotels are also named among the affected organizations. None of the companies have issued a public statement confirming or denying the claims as of this writing, so these figures should be treated as the attacker’s own account of the intrusion rather than independently verified totals.

Azure Active Directory, now called Microsoft Entra ID, is the identity and access system many large organizations use to manage employee logins, permissions, and group memberships across their corporate networks. It is a central piece of infrastructure, which is exactly what makes it a valuable target: gaining access to it does not just expose one application, it exposes the map of who has access to what across an entire company.

Based on the available reporting, the attacker did not exploit a flaw in Azure or Entra itself. Instead, the access came from credentials harvested through infostealer malware, a type of malicious software that quietly collects saved passwords, browser session tokens, and login details from an infected device and sends them back to the attacker. Once those credentials are in hand, they can be used to log into cloud services directly, without needing to bypass any additional technical defenses, provided multi-factor authentication was not enforced or was itself compromised.

The data reportedly stolen goes beyond basic contact information. It includes employee directories with names, corporate email addresses, physical addresses, phone numbers, employee ID numbers, job titles, and reporting lines showing who manages whom. Also included, according to the reporting, are records for service accounts and privileged administrator accounts, the kind of internal accounts used to run automated systems or manage IT infrastructure.

Threat intelligence firm Hudson Rock reviewed the claims and warned that the inclusion of service account and global administrator names is especially concerning. In the firm’s assessment, that information effectively hands attackers a roadmap for follow-up attacks, since knowing exactly which accounts hold the highest level of access makes it far easier to plan targeted phishing or social engineering attempts against the people who control them.

No CVE has been assigned in connection with this campaign, since the reported access relied on stolen credentials rather than a software vulnerability. As of publication, none of the named companies had issued a public statement, and the claims rest on the threat actor’s own postings along with third-party analysis of the data samples.

Source: SecurityWeek, “Fortune 500 Companies Hit in Azure Data Theft Campaign”

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular