Millions of stolen records allegedly dumped online by mystery "Hatman" hacker — Mc Donalds, Vodafone and more see Microsoft Azure records stolen | Tech Radar
Overview
News, deals, reviews, guides and more on the newest computing gadgets
Start exploring exclusive deals, expert advice and more
Details
Unlock and manage exclusive Techradar member rewards.
Unlock instant access to exclusive member features.
Get full access to premium articles, exclusive features and a growing list of member rewards.
Millions of stolen records allegedly dumped online by mystery "Hatman" hacker — Mc Donalds, Vodafone and more see Microsoft Azure records stolen
When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.
Hacker “The Hatman” claims to have stolen millions of Azure/Entra employee records from major firms
Data includes names, emails, job titles, privileged accounts; risks include impersonation and fraud
Victims dispute scope, but researchers say infostealer‑based theft makes the leaks likely authentic
A cybercriminal is selling millions of user records on the dark web, which they claim to have stolen from large organizations such as Mc Donalds, Tata Consultancy Services, and Wyndham Hotels.
A hacker going by the alias “The Hatman” posted multiple threads on dark web forums, claiming to have stolen information from Azure and Entra environments.
Among the victims and the number of records exposed, are:
Mc Donald’s Corporation: 1,700,000 records TCS (Tata Consultancy Services): 800,000 records Vodafone: 425,000 records HCL Technologies: 250,000 records Inter Continental Hotels Group (IHG): 185,000 records Kyndryl: 170,000 records Gap Inc.: 80,000 records Hexaware Technologies: 20,000 records Wyndham Hotels: 9,000 records
Hackers claim to be selling 340 million stolen Only Fans records
Experts warn "colossal" breach exposes 24 billion records including personal info
Accenture confirms breach after hacker steals 35GB of source code and other data
They are now looking for a buyer: “I’m selling Mc Donald’s Corporation internal employee dump downloaded directly from Azure Tenant using compromised credentials,” The Hatman said in one of the posts.
In their writeup, security researchers from Cybernews said they analyzed one of the samples posted on the dark web and said the entries were “consistent with Azure directory exports”.
They contained employee names, emails, phone numbers, job titles, workplace addresses, IDs, the departments they work in, user group memberships, service accounts, and highly privileged account records.
Stealing information such as names, email addresses, and workplace details might not sound like a worrisome breach of privacy, but the implications are rather big. Cybercriminals can use it to impersonate a business partner or a major client, and try to trick their employees into installing ransomware, or making a fraudulent wire transaction. That way, they can escalate what seems like a relatively benign breach, into a full-blown cyberattack with material and legal consequences.
For example, a criminal might discover a Vodafone employee that regularly handles payments to a particular supplier. They might impersonate that supplier’s finance director, engage in conversation and, while requesting a new payment, warn that the company changed their bank account. This is not a purely theoretical scenario - it’s been documented time and time again.
US healthcare software giant Unlimited Technology Systems admits hackers may have stolen sensitive data of 3.8 million people
Levi's reveals security tear may have let hackers steal important corporate data
Fortinet firewalls hit by huge password-stealing attack — around 75,000 users possibly affected
Most organizations are yet to give an official statement about these claims. Gap told Bleeping Computer that it found no evidence of the breach and suggested that the attackers merely repackaged data from an older incident.
“Our preliminary investigation indicates that the data in question is limited in scope, non-sensitive and dated back to several years ago. Notably, there is no evidence to suggest that our corporate systems have been compromised,” Gap told the publication.
Tata Consultancy Services notified the Indian National Stock Exchange about the breach last week, also suggesting that this was a resurfacing of an older incident.
“The Company has investigated the matter and has not found any credible evidence of a breach of TCS systems or customer environments,” TCS said in the filing. “The information referenced appears to be more than four years old and limited to basic employee information. There is no indication that customer data, customer systems, or TCS operational systems have been impacted.”
TCS said the attackers broke in using credential stuffing, something that could have only been done years ago: “The attacker claims to have used password spray and Multi-Factor Authentication (MFA) fatigue as the attack vector. The Company has had strong safeguards in place against such techniques for more than two years.”
“Judging by the massive size of the organizations impacted, it appears highly likely that this campaign originates from targeted exploitation of Infostealer infections rather than a systemic zero-day vulnerability in Azure,” the researchers said in their report. “If this were a widespread vulnerability, we would likely see a much broader spectrum of organizations impacted, including smaller businesses, rather than just these massive Fortune 500-level enterprises.”
Hudson Rock also described the stolen data as “likely highly authentic”, hinting that just because it’s older, it doesn’t mean it’s not useful.
➡️ Read our full guide to the best antivirus
- Best overall: Bitdefender Total Security
- Best for families: Norton 360 with Life Lock
- Best for mobile: Mc Afee Mobile Security
Follow Tech Radar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, Io T, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.
You must confirm your public display name before commenting
Spotify launches Playlist Notes for personal commentary on songs
This lifesaving patch buzzes your arm when it detects nearby poisons
'You come to witness both the light and dark sides of your own reign': we chat to Team Ninja about Nioh 3: Hell Rising and all the changes it brings to 2026's best soulslike game
Sony launches new 'It Happens on PS5' ad featuring GTA 6, but it can't escape angry fans — 'Discs used to happen on PS5'
Tech Radar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.
© Future US, Inc. Full 7th Floor, 130 West 42nd Street, New York, NY 10036.
Key Takeaways
- News, deals, reviews, guides and more on the newest computing gadgets
- Start exploring exclusive deals, expert advice and more
- Unlock and manage exclusive Techradar member rewards
- Unlock instant access to exclusive member features
- Get full access to premium articles, exclusive features and a growing list of member rewards



