VYPR
breachPublished Aug 16, 2026· Updated Aug 18, 2026· 5 sources

Massive Azure Credential Theft Campaign Exposes Millions of Records from McDonald's, Vodafone, and More

A threat actor known as 'TheHatman' is selling vast amounts of stolen employee data from major corporations, including McDonald's and Vodafone, exfiltrated from Azure and Entra tenants using compromised credentials.

A significant data exfiltration campaign is underway on dark web forums, where a threat actor identified as "TheHatman" is systematically selling large volumes of internal employee data stolen from major global corporations. The actor claims to have accessed these records directly from victim organizations' Azure and Entra tenants by leveraging compromised credentials. The scale of the operation is substantial, with "TheHatman" listing data from at least nine Fortune 500 companies across various sectors including IT services, hospitality, telecommunications, and retail.

Among the most prominent victims are McDonald's Corporation, with over 1.7 million exposed records, followed by Tata Consultancy Services with approximately 800,000, and Vodafone with around 425,000 records. Other affected companies include HCL Technologies, InterContinental Hotels Group, Kyndryl, Gap Inc., Hexaware Technologies, and Wyndham Hotels, with data dumps ranging from tens of thousands to hundreds of thousands of records.

Researchers from Hudson Rock, who have analyzed sample datasets, confirm the high credibility of the information. The leaked data consistently includes corporate email addresses, phone numbers, physical addresses, employee IDs, job titles, departments, and manager assignments. Crucially, the datasets also contain access and group mapping information, including details on service accounts and, in some instances, Global Administrator accounts, providing attackers with a clear roadmap for further exploitation.

While "TheHatman" asserts that compromised credentials were the sole method of access, the exact initial entry point remains unconfirmed. Potential vectors include infostealer malware harvesting session tokens from employee devices, successful phishing campaigns yielding administrative access, inadequate multi-factor authentication (MFA) enforcement within affected tenants, or the abuse of third-party APIs with overly broad permissions. The consistent format and rapid dissemination of the data suggest a highly systematized, likely automated, process once initial access was gained.

Hudson Rock researchers have also identified compromised Azure credentials linked to infostealer infections on devices belonging to employees at several of the affected companies, including TCS, Gap Inc., HCL Technologies, and Kyndryl. In one documented case, a single compromised device contained numerous corporate credentials and session cookies, granting direct access to a Kyndryl Azure Active Directory account.

The nature of the victims—large multinational corporations rather than a broad range of smaller businesses—strongly suggests that this campaign targets stolen credentials specifically, rather than exploiting a systemic vulnerability within the Azure platform itself. This indicates a focus on high-value enterprise access.

The real-world implications of this breach extend far beyond the initial data exposure. Threat actors frequently weaponize such structured directory information to conduct highly convincing business email compromise (BEC) and spear-phishing attacks. The detailed reporting lines and job titles enable impersonation of management or IT staff, facilitating fraudulent financial transfers or the coercion of employees into divulging MFA codes.

Furthermore, the exposure of service account and administrator names provides initial access brokers and ransomware groups with valuable intelligence for identifying and targeting critical infrastructure. Organizations are urged to prioritize credential hygiene, implement continuous monitoring for infostealer-compromised credentials, enforce robust MFA across all tenant portals, and rigorously scrutinize third-party API permissions to mitigate the risk of similar attacks.

This new report details the specific method of data exfiltration, which involved using compromised credentials likely obtained through a targeted infostealer campaign. The threat actor, known as 'TheHatman', specifically targeted Azure/Entra instances, and the compromised data includes sensitive employee information such as service accounts and global admin names, which pose a significant risk for further targeted attacks.

The Register article provides additional details on the alleged data breach, noting that the threat actor known as "TheHatman" claims to have used password spray and MFA fatigue as attack vectors. While Hudson Rock assesses the data as highly likely authentic and containing privileged account information, Tata Consultancy Services has stated that their investigation found no credible evidence of a breach of their systems or customer environments, and that the referenced information appears to be over four years old and limited to basic employee details.

The cybercriminal known as 'TheHatman' is actively advertising stolen data from major corporations, including McDonald's, Vodafone, and Tata Consultancy Services, on underground forums. The data, allegedly exfiltrated from Microsoft Azure environments via Entra ID portals, includes employee records, service account information, and potentially global administrator credentials. While the exact attack vector remains under investigation, threat intelligence firms suggest methods like password spraying and MFA fatigue could have been employed.

The threat actor, identified as 'TheHatman,' claims to have exfiltrated millions of employee records from the Azure tenants of multiple Fortune 500 companies, including McDonald's, Vodafone, Kyndryl, and TCS. These claims are supported by the actor's recent posts on cybercrime forums, where large internal directories allegedly extracted directly from victim Azure environments have been shared. This incident further details the scope and specific targets of the credential theft campaign previously reported.

Synthesized by Vypr AI