Abstract illustration of the McDonald's Azure breach showing a cracked cloud icon above a corporate tower
🔴 Cybersecurity · Data Breach

McDonald’s Azure Breach Exposes
1.7 Million Employee Records

A hacker calling himself TheHatman says he pulled 3.64 million records from 9 Fortune 500 companies, and nobody has confirmed how he got in.

📅 August 2026 ⏱ 8 min read
3.64M records claimed stolen from 9 firms
McDonald’s hit hardest, 1.7M records
Zero confirmed Azure vulnerabilities
Top Target
McDonald’s
1.7 M
Companies Hit
Global Enterprises
9
Azure Flaw
Zero-Days Found
0

A hacker calling himself TheHatman triggered a sprawling Azure breach that’s now touching nine Fortune 500 companies, and it didn’t take a zero-day to pull it off. Starting July 31, TheHatman began posting internal employee directories on cybercrime forums including DarkForum, PwnForums, and BreachForumsSt, claiming each one was pulled directly from the victim’s Azure tenant. McDonald’s tops the list with 1.7 million records, the largest single haul in the campaign so far.

Here’s what actually happened, according to researchers at Hudson Rock who reviewed sample datasets: none of this required breaking through Azure’s front door. The data is “consistent with Azure directory exports,” and the likely entry point was compromised credentials, quite possibly harvested by infostealer malware sitting on employee machines for months before anyone noticed.

This piece breaks down exactly what’s inside the leaked directories, what McDonald’s, Gap, and TCS have said in response, and what security teams running on Azure should actually be doing about it right now.

📋 What This Azure Breach Boils Down To
Who

Who The Azure Breach Hit

Nine organizations across retail, IT services, telecom, hospitality, and logistics — including McDonald’s, TCS, Vodafone, and HCL Technologies.

How

How It Happened

Compromised Azure and Entra ID credentials, most likely harvested by infostealer malware — not a platform-wide software flaw.

Response

Company Pushback

Gap and TCS both say they found no evidence of a breach and describe the data as old and low-sensitivity.

Risk

Why It Still Matters

Even “boring” fields like job titles and org charts give scammers exactly what they need to run convincing phishing attacks.

Inside the Azure Breach Timeline
01

July 31: The Azure Breach Timeline Begins

Origin

TheHatman’s first listings appeared on cybercrime forums in late July, offering internal employee data pulled from corporate Azure tenants. Each post came with a sample dataset so potential buyers could verify the goods before paying — a common tactic among data brokers trying to build credibility on underground marketplaces.

💡 Why it spread fast. Once one dump sold, TheHatman kept the momentum going, posting a new company’s directory every few days through mid-August.
02

McDonald’s Tops the Azure Breach Records List

Largest Haul

The McDonald’s listing, posted around August 16, is the largest single dataset in the campaign at an estimated 1.7 million records. TheHatman described it as an “internal employee dump downloaded directly from Azure Tenant using compromised credentials,” and said it includes names, employee IDs, email addresses, job titles, phone numbers, postal addresses, service accounts, and other tenant account records.

💡 What’s not confirmed. McDonald’s has not issued a public statement addressing the specific claims as of this writing.
03

Inside the Azure Breach: How Credentials Got Stolen

Root Cause

Security researchers at Hudson Rock say they traced compromised Azure credentials linked to infostealer malware infections at several of the affected companies, including TCS, Gap, HCL Technologies, and Kyndryl. Infostealers quietly harvest saved passwords, browser data, and session cookies from an infected machine — and stolen session tokens can sometimes let an attacker skip the login screen (and MFA) entirely.

The exact entry point is still unconfirmed, but researchers point to a few likely explanations: phishing that yielded admin-level access, tenants without strict MFA enforcement, or an integration with overly broad read permissions.

💡 The real takeaway. This looks like a systematic credential-harvesting operation, not a hole in Azure itself.
04

Companies Respond to the Azure Breach Claims

Pushback

Gap told reporters its preliminary investigation found the advertised data “limited in scope, non-sensitive, and dated back several years,” with no evidence its corporate systems were compromised. TCS gave a similar statement to India’s National Stock Exchange, saying its review turned up no credible evidence of an intrusion and that the data appears to be more than four years old.

💡 Worth noting. Neither denial rules out that the data is real — only that it may be older or less sensitive than TheHatman’s marketing suggests.

Nine companies breached the same way:
one stolen password, not one hacked system.

Pattern Identified By Hudson Rock
🔒 If Your Company Runs on Azure, Do This Now
  • Turn on phishing-resistant MFA (FIDO2 keys or passkeys) for every Entra ID account, not just admins.
  • Check for infostealer exposure — run employee credentials against known infostealer and breach databases.
  • Enforce Conditional Access and Continuous Access Evaluation so stolen session tokens expire faster.
  • Train staff on org-chart phishing — leaked job titles and reporting lines make impersonation scams far more convincing.
  • Rotate credentials for any device with a history of malware infections, even if the infection is “old.”

⚠️ Why This Azure Breach Still Matters If The Data Is “Old”

1. Org charts don’t expire. A four-year-old directory still tells a scammer who approves invoices, who reports to whom, and which employee handles vendor payments.

2. It fuels business email compromise. Attackers can use a real employee’s name, title, and workplace details to impersonate a supplier or a manager and request a fraudulent wire transfer.

3. MFA gaps outlast the leak. If credentials were reused or MFA wasn’t enforced when the data was taken, that same weakness may still exist today.

✅ Final Verdict

The Azure Breach, What to Remember

1
3.64M records claimed across 9 Fortune 500 companies since July 31, 2026
2
McDonald’s is the largest target — an estimated 1.7 million employee records
3
No confirmed Azure vulnerability — compromised credentials, likely via infostealer malware
4
Gap and TCS dispute the claims, calling the data old and low-sensitivity
5
The real danger isn’t the leak itself — it’s the phishing and BEC attacks it enables
🔗 BleepingComputer broke the original reporting on TheHatman’s forum posts, including direct quotes from the seller — read the full writeup at BleepingComputer.
💬 Frequently Asked Questions
Q. Is the McDonald’s Azure breach officially confirmed?
Not fully. TheHatman’s claims are unverified by the companies themselves, though Hudson Rock and other researchers say sample data looks consistent with real Azure directory exports. McDonald’s has not issued a public statement on the specific claims as of this writing.
Q. What can criminals actually do with a stolen employee directory?
More than you’d think. Names, titles, phone numbers, and reporting structures are exactly what’s needed to run convincing phishing emails, fake IT support calls, or business email compromise scams targeting finance teams.
Q. Should employees at these companies change their passwords?
Yes, as a precaution. Even if a company disputes the breach, rotating passwords and enabling phishing-resistant MFA costs little and closes off a common attack path.
Q. How did TheHatman reportedly get into these Azure tenants?
Researchers believe compromised credentials, likely harvested by infostealer malware, gave access to Azure and Entra ID environments. No Azure zero-day or platform vulnerability has been confirmed.
Editor’s Note. This article draws on reporting from BleepingComputer, Hudson Rock, Cybernews, SecurityWeek, TechRadar, and eSecurity Planet, all published in August 2026. Company statements are quoted as reported by BleepingComputer.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top