Tuesday, 18 August 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
Technology

Millions of stolen records allegedly dumped online by mystery "Hatman" hacker — McDonalds, Vodafone and more see Microsoft Azure records stolen

TechRadar ·
Millions of stolen records allegedly dumped online by mystery "Hatman" hacker — McDonalds, Vodafone and more see Microsoft Azure records stolen

Hacker “TheHatman” claims to have stolen millions of Azure/Entra employee records from major firms Data includes names, emails, job titles, privileged accounts; risks include impersonation and fraud Victims dispute scope, but researchers say infostealer‑based theft makes the leaks likely authentic A cybercriminal is selling millions of user records on the dark web, which they claim to have stolen from large organizations such as McDonalds, Tata Consultancy Services, and Wyndham Hotels.

A hacker going by the alias “TheHatman” posted multiple threads on dark web forums, claiming to have stolen information from Azure and Entra environments.

TheHatman said they broke in using compromised login credentials, targeting almost a dozen organizations.

What was stolen and from whom? Among the victims and the number of records exposed, are: McDonald’s Corporation: 1,700,000 records TCS (Tata Consultancy Services): 800,000 records Vodafone: 425,000 records HCL Technologies: 250,000 records InterContinental Hotels Group (IHG): 185,000 records Kyndryl: 170,000 records Gap Inc.: 80,000 records Hexaware Technologies: 20,000 records Wyndham Hotels: 9,000 records They are now looking for a buyer: “I’m selling McDonald’s Corporation internal employee dump downloaded directly from Azure Tenant using compromised credentials,” TheHatman said in one of the posts.

In their writeup, security researchers from Cybernews said they analyzed one of the samples posted on the dark web and said the entries were “consistent with Azure directory exports”.

They contained employee names, emails, phone numbers, job titles, workplace addresses, IDs, the departments they work in, user group memberships, service accounts, and highly privileged account records.

What are the risks? Stealing information such as names, email addresses, and workplace details might not sound like a worrisome breach of privacy, but the implications are rather big.

Cybercriminals can use it to impersonate a business partner or a major client, and try to trick their employees into installing ransomware , or making a fraudulent wire transaction.

That way, they can escalate what seems like a relatively benign breach, into a full-blown cyberattack with material and legal consequences.

For example, a criminal might discover a Vodafone employee that regularly handles payments to a particular supplier.

They might impersonate that supplier’s finance director, engage in conversation and, while requesting a new payment, warn that the company changed their bank account.

This is not a purely theoretical scenario - it’s been documented time and time again.

What did the victims say? Most organizations are yet to give an official statement about these claims.

Read the full article on TechRadar ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.

More from TechRadar

See all ›

More in Technology

See all ›