AI News Feed
Market watch
Cybersecurity

Hacker claims to have stolen millions of employee records from McDonald's, Vodafone and other major companies

A dark web seller called TheHatman is selling millions of Azure/Entra employee records claimed to be from McDonald's, Vodafone, TCS and others. Researchers say the data looks authentic; victims say it's old or non-sensitive.

According to a report by TechRadar, TheHatman posted multiple threads on dark web forums saying the data was obtained using compromised login credentials. The claimed victim list includes McDonald's Corporation with 1.7 million records, TCS with 800,000, Vodafone with 425,000, HCL Technologies with 250,000, InterContinental Hotels Group with 185,000, Kyndryl with 170,000, Gap Inc. with 80,000, Hexaware Technologies with 20,000, and Wyndham Hotels with 9,000.

"I'm selling McDonald's Corporation internal employee dump downloaded directly from Azure Tenant using compromised credentials," TheHatman said in one of the posts. Security researchers from Cybernews, cited by TechRadar, analyzed sample entries and found them consistent with Azure directory exports, containing employee names, emails, phone numbers, job titles, workplace addresses, IDs, departments, user group memberships, service accounts, and highly privileged account records.

The risk is significant, as this information can be used for impersonation and fraud. For example, a criminal could impersonate a supplier's finance director and trick a company into sending a fraudulent payment. This scenario has been documented repeatedly.

Most victims have not commented publicly. Gap told BleepingComputer that its preliminary investigation found no evidence of the breach and suggested the data is non-sensitive and dated from years ago. TCS notified the Indian National Stock Exchange, stating that it found no credible evidence of a breach of its systems, and that the information appears to be more than four years old and limited to basic employee information. TCS also claimed the attacker used password spray and MFA fatigue, techniques the company has had safeguards against for more than two years.

However, security researchers from Hudson Rock disagree with that assessment. They believe the attackers stole login credentials using an infostealer, not password spraying. "Judging by the massive size of the organizations impacted, it appears highly likely that this campaign originates from targeted exploitation of Infostealer infections rather than a systemic zero-day vulnerability in Azure," they said. Hudson Rock described the stolen data as "likely highly authentic," suggesting that even older data can still be useful to criminals.