Millions of stolen records allegedly dumped online by mystery "Hatman" hacker
McDonalds, Vodafone and more see Microsoft Azure records stolen
Date:
Tue, 18 Aug 2026 13:00:00 +0000
Description:
Some affected companies argue the data is years old and claim no breach in their systems.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Hacker TheHatman claims to have stolen millions of Azure/Entra employee records from major firms Data
includes names, emails, job titles, privileged accounts; risks include impersonation and fraud Victims dispute scope, but researchers say infostealerbased theft makes the leaks likely authentic A cybercriminal is selling millions of user records on the dark web, which they claim to have stolen from large organizations such as McDonalds, Tata Consultancy Services, and Wyndham Hotels.
A hacker going by the alias TheHatman posted multiple threads on dark web forums, claiming to have stolen information from Azure and Entra
environments. TheHatman said they broke in using compromised login credentials, targeting almost a dozen organizations. Latest Videos From TechRadar Watch full video here: What was stolen and from whom? Among the victims and the number of records exposed, are:
McDonalds Corporation: 1,700,000 records TCS (Tata Consultancy Services): 800,000 records Vodafone: 425,000 records HCL Technologies: 250,000 records InterContinental Hotels Group (IHG): 185,000 records Kyndryl: 170,000 records Gap Inc.: 80,000 records Hexaware Technologies: 20,000 records Wyndham
Hotels: 9,000 records You may like Hackers claim to be selling 340 million stolen OnlyFans records Experts warn "colossal" breach exposes 24 billion records including personal info Accenture confirms breach after hacker steals 35GB of source code and other data
They are now looking for a buyer: Im selling McDonalds Corporation internal employee dump downloaded directly from Azure Tenant using compromised credentials, TheHatman said in one of the posts.
In their writeup, security researchers from Cybernews said they analyzed one of the samples posted on the dark web and said the entries were consistent with Azure directory exports. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.
They contained employee names, emails, phone numbers, job titles, workplace addresses, IDs, the departments they work in, user group memberships, service accounts, and highly privileged account records. What are the risks? Stealing information such as names, email addresses, and workplace details might not sound like a worrisome breach of privacy, but the implications are rather
big. Cybercriminals can use it to impersonate a business partner or a major client, and try to trick their employees into installing ransomware , or making a fraudulent wire transaction. That way, they can escalate what seems like a relatively benign breach, into a full-blown cyberattack with material and legal consequences.
For example, a criminal might discover a Vodafone employee that regularly handles payments to a particular supplier. They might impersonate that suppliers finance director, engage in conversation and, while requesting a
new payment, warn that the company changed their bank account. This is not a purely theoretical scenario - its been documented time and time again. What
to read next US healthcare software giant Unlimited Technology Systems admits hackers may have stolen sensitive data of 3.8 million people Levi's reveals security tear may have let hackers steal important corporate data Fortinet firewalls hit by huge password-stealing attack around 75,000 users possibly affected What did the victims say? Most organizations are yet to give an official statement about these claims. Gap told BleepingComputer that it
found no evidence of the breach and suggested that the attackers merely repackaged data from an older incident.
Our preliminary investigation indicates that the data in question is limited in scope, non-sensitive and dated back to several years ago. Notably, there
is no evidence to suggest that our corporate systems have been compromised, Gap told the publication.
Tata Consultancy Services notified the Indian National Stock Exchange about the breach last week, also suggesting that this was a resurfacing of an older incident.
The Company has investigated the matter and has not found any credible evidence of a breach of TCS systems or customer environments, TCS said in the filing. The information referenced appears to be more than four years old and limited to basic employee information. There is no indication that customer data, customer systems, or TCS operational systems have been impacted.
TCS said the attackers broke in using credential stuffing, something that could have only been done years ago: The attacker claims to have used
password spray and Multi-Factor Authentication (MFA) fatigue as the attack vector. The Company has had strong safeguards in place against such
techniques for more than two years.
Not everyone agrees with that assessment, though. Security researchers Hudson Rock believe the attackers stole login credentials with an infostealer , rather than through password spraying.
Judging by the massive size of the organizations impacted, it appears highly likely that this campaign originates from targeted exploitation of
Infostealer infections rather than a systemic zero-day vulnerability in
Azure, the researchers said in their report. If this were a widespread vulnerability, we would likely see a much broader spectrum of organizations impacted, including smaller businesses, rather than just these massive
Fortune 500-level enterprises.
Hudson Rock also described the stolen data as likely highly authentic,
hinting that just because its older, it doesnt mean its not useful. The best antivirus for all budgets Our top picks, based on real-world testing and comparisons
Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/millions-of-stolen-records-allegedly-du mped-online-by-mystery-hatman-hacker-mcdonalds-vodafone-and-more-see-microsoft -azure-records-stolen
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)