Massive Employee Data Breach Allegedly Hits Microsoft Azure Customers, Including McDonald’s and Vodafone
A threat actor known as TheHatman claims to have stolen millions of employee records from Microsoft Azure environments belonging to nine major corporations, including McDonald’s, Vodafone, Tata Consultancy Services (TCS), and Kyndryl. The stolen data, advertised for sale, reportedly includes 1.7 million records from McDonald’s the largest dataset alongside hundreds of thousands from other firms like HCL Technologies, IHG Hotels & Resorts, Gap, and Wyndham Hotels & Resorts.
Cybersecurity firm Hudson Rock, which uncovered the breach, assessed the data as "highly likely authentic," noting that the records contain far more than basic contact details. Samples reviewed by the firm include phone numbers, physical addresses, employee IDs, job titles, department structures, office locations, and even accounts with Global Administrator privileges potentially giving attackers a roadmap for targeted phishing or privilege escalation.
The method of compromise remains unclear. TheHatman claims to have used compromised credentials, but Hudson Rock could not verify the initial access vector. Possible entry points include infostealer malware, phishing, weak or missing multi-factor authentication (MFA), or overly permissive third-party applications. The firm’s analysis suggests the breach likely stems from targeted infostealer infections rather than a widespread Azure vulnerability, as the affected organizations are predominantly large enterprises.
Responses from the impacted companies have been mixed. Tata Consultancy Services acknowledged receiving threat intelligence alerts about potential exposure of employee data but stated that its investigation found no evidence of a breach in its systems or customer environments. The company noted that the allegedly exposed data appears to be outdated (over four years old) and limited to basic employee information, with no impact on customer or operational systems. TCS also claimed its security controls including protections against password spraying and MFA fatigue remain effective.
Microsoft and the other named organizations have not yet provided public confirmation of the breach or its scope. The full extent of the incident, including how the attacker exfiltrated data from multiple corporate Azure directories, remains under investigation.
IHG Hotels & Resorts cybersecurity rating report: https://www.rankiteo.com/company/ihghotels&resorts
HCLTech cybersecurity rating report: https://www.rankiteo.com/company/hcltech
Gap cybersecurity rating report: https://www.rankiteo.com/company/gap-inc--gap
Wyndham Hotels & Resorts Development cybersecurity rating report: https://www.rankiteo.com/company/wyndham-hotels-resorts-development-
McDonald's cybersecurity rating report: https://www.rankiteo.com/company/mcdonald's-corporation
Vodafone cybersecurity rating report: https://www.rankiteo.com/company/vodafone
Kyndryl cybersecurity rating report: https://www.rankiteo.com/company/kyndryl
Microsoft cybersecurity rating report: https://www.rankiteo.com/company/microsoft
"id": "IHGHCLGAPWYNMCDVODKYNMIC1786975327",
"linkid": "ihghotels&resorts, hcltech, gap-inc--gap, wyndham-hotels-resorts-development-, mcdonald's-corporation, vodafone, kyndryl, microsoft",
"type": "Breach",
"date": "5/2022",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '1.7 million employee records',
'industry': 'Fast Food',
'name': 'McDonald’s',
'size': 'Large',
'type': 'Corporation'},
{'customers_affected': 'Hundreds of thousands of '
'employee records',
'industry': 'Telecommunications',
'name': 'Vodafone',
'size': 'Large',
'type': 'Corporation'},
{'customers_affected': 'Hundreds of thousands of '
'employee records (allegedly '
'outdated)',
'industry': 'Information Technology',
'name': 'Tata Consultancy Services (TCS)',
'size': 'Large',
'type': 'Corporation'},
{'customers_affected': 'Hundreds of thousands of '
'employee records',
'industry': 'Information Technology',
'name': 'Kyndryl',
'size': 'Large',
'type': 'Corporation'},
{'customers_affected': 'Hundreds of thousands of '
'employee records',
'industry': 'Information Technology',
'name': 'HCL Technologies',
'size': 'Large',
'type': 'Corporation'},
{'customers_affected': 'Hundreds of thousands of '
'employee records',
'industry': 'Hospitality',
'name': 'IHG Hotels & Resorts',
'size': 'Large',
'type': 'Corporation'},
{'customers_affected': 'Hundreds of thousands of '
'employee records',
'industry': 'Retail',
'name': 'Gap',
'size': 'Large',
'type': 'Corporation'},
{'customers_affected': 'Hundreds of thousands of '
'employee records',
'industry': 'Hospitality',
'name': 'Wyndham Hotels & Resorts',
'size': 'Large',
'type': 'Corporation'}],
'attack_vector': 'Compromised credentials (alleged)',
'data_breach': {'data_exfiltration': 'Yes (advertised for sale)',
'number_of_records_exposed': 'Millions (1.7M+ from McDonald’s '
'alone)',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High (PII, administrative privileges)',
'type_of_data_compromised': ['Employee IDs',
'Job titles',
'Department structures',
'Office locations',
'Phone numbers',
'Physical addresses',
'Global Administrator accounts']},
'description': 'A threat actor known as *TheHatman* claims to have stolen '
'millions of employee records from Microsoft Azure '
'environments belonging to nine major corporations, including '
'McDonald’s, Vodafone, Tata Consultancy Services (TCS), and '
'Kyndryl. The stolen data includes sensitive employee '
'information such as phone numbers, physical addresses, '
'employee IDs, job titles, department structures, office '
'locations, and accounts with *Global Administrator* '
'privileges.',
'impact': {'data_compromised': 'Employee records (1.7M+ from McDonald’s, '
'hundreds of thousands from others)',
'identity_theft_risk': 'High (PII exposed)',
'systems_affected': 'Microsoft Azure environments'},
'initial_access_broker': {'data_sold_on_dark_web': 'Yes',
'entry_point': 'Compromised credentials (alleged)',
'high_value_targets': 'Global Administrator '
'accounts'},
'investigation_status': 'Ongoing',
'motivation': 'Financial gain (data sold on dark web)',
'post_incident_analysis': {'root_causes': 'Possible infostealer malware, '
'phishing, weak/missing MFA, or '
'overly permissive third-party '
'applications'},
'references': [{'source': 'Hudson Rock'}],
'response': {'communication_strategy': 'Mixed responses from affected '
'companies (e.g., TCS acknowledged '
'alerts but denied breach impact)',
'third_party_assistance': 'Hudson Rock (cybersecurity firm)'},
'threat_actor': 'TheHatman',
'title': 'Massive Employee Data Breach Allegedly Hits Microsoft Azure '
'Customers, Including McDonald’s and Vodafone',
'type': 'Data Breach'}