
A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials.
Starting July 31st, multiple posts from someone using the alias “TheHatman” advertised data dumps from major organizations, including McDonald's, Gap Inc., Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels (IHG), and Kyndryl.
In total, the threat actor claims to have 3.64 million data records, with the most recent breach posted on Sunday, containing an alleged 1.7 million employee records from McDonalds.
“I’m selling McDonald’s Corporation internal employee dump downloaded directly from Azure Tenant using compromised credentials,” the threat actor says in the post.
| Company | Size | Type | Data type |
| McDonalds | 1.7+ million records | Azure Internal Employee Dump | Full Name, Email, Title, Phone, Address |
| Gap Inc. | 80,000+ records | Azure Internal Employee Dump | Full Name, Email, Title, Phone, Address |
| Vodafone | 425,000+ records | Azure Internal Employee Dump | Full Name, Email, Title, Phone, Address |
| TCS (Tata Consultancy) | 800,000+ records | Azure dump | Full Name, Email, Title, Phone, Address |
| HCL Technologies | 250,000+ records | Azure dump | Full Name, Email, Title, Phone, Address |
| InterContinental Hotels | 185,000+ records | Azure dump | Full Name, Email, Title, Phone, Address |
| Wyndham Hotels | 9,000+ records | Azure/Entra dump | Full Name, Email, Title, Phone, Address |
| Hexaware | 20,000+ records | Azure/Entra dump | Full Name, Email, Employee ID, Phone, Address |
| Kyndryl.com | 170,000+ records | Azure/Entra dump | Employee accounts, service accounts, and other tenant account records. |
