McDonald’s, Vodafone, and TCS Hit in Azure Data Theft Campaign Exposing Millions of Enterprise Records

McDonald’s, Vodafone, and TCS Hit in Azure Data Theft Campaign Exposing Millions of Enterprise Records

A threat actor says millions of employee records were stolen from major companies through Microsoft Azure. Here’s what was taken, why it matters, and how you can reduce your risk.

What Happened in the Azure Data Theft Campaign?

According to SecurityWeek, a threat actor called TheHatman is selling data said to come from several major companies.

The companies include McDonald’s, Tata Consultancy Services (TCS), Vodafone, HCL Technologies, IHG, Kyndryl, Gap, Hexaware Technologies, and Wyndham Hotels.

The data was reportedly taken from company systems hosted through Microsoft Azure and Entra. These services help businesses manage cloud resources and employee accounts.

Security firm Hudson Rock reviewed the information and said the employee directories appear legitimate. However, the theft claims have not been fully confirmed by every affected company.

The stolen records could help criminals create highly convincing phishing emails and fake business messages.

And this risk goes beyond the companies named in this incident. Your information may already appear in data stolen during another breach you never heard about.

If you are unsure whether your information was leaked somewhere online, automatic monitoring can help you spot problems earlier.

Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.

Which Companies Were Affected and What Data Was Stolen?

The largest dataset is linked to McDonald’s and contains more than 1.7 million records, according to Hudson Rock.

Other reported datasets include:

  • Tata Consultancy Services: about 800,000 records
  • Vodafone: about 425,000 records
  • HCL Technologies: about 250,000 records
  • InterContinental Hotels Group: about 185,000 records

The source did not provide record totals for every company involved.

The stolen information reportedly includes employee names, corporate email addresses, phone numbers, addresses, employee IDs, and job titles.

It may also include manager details, company group memberships, service accounts, and records connected to highly privileged company accounts.

These details can reveal how a company is organized and which employees have important access.

Keep your personal information scam-proof

Futureproof keeps your data safer with simple guidance to set a strong password, turn on 2-step verification, and lock down your account.

Check my safety

How Stolen Login Details May Have Opened the Door

According to Hudson Rock, stolen login details were likely used to enter the affected Azure and Entra systems.

The security firm connected many of those credentials to an infostealer campaign.

An infostealer is harmful software that quietly steals information such as usernames, passwords, and other login details from a device.

Criminals may then use those details to enter company systems without needing to break passwords themselves.

However, the exact attack path has not been fully confirmed.