Hackers dumping millions of records from McDonald’s, Vodafone, and other Fortune 500 companies

A threat actor has flooded the underground forums with datasets for sale, allegedly stolen from the Microsoft Azure and Entra cloud environments of some of the world’s largest companies, exposing information that could help criminals target employees.

The attacker, going under the alias “TheHatman,” has posted data linked to at least 9 major enterprises on underground forums over the past week:

  • McDonald’s Corporation: 1,700,000 records
  • TCS (Tata Consultancy Services): 800,000 records
  • Vodafone: 425,000 records
  • HCL Technologies: 250,000 records
  • InterContinental Hotels Group (IHG): 185,000 records
  • Kyndryl: 170,000 records
  • Gap Inc.: 80,000 records
  • Hexaware Technologies: 20,000 records
  • Wyndham Hotels: 9,000 records

To prove their claims, the attacker shared data samples. While the download link to McDonald’s data sample was not functional when Cybernews researchers checked, the other companies’ entries revealed what kinds of data may be included in the allegedly stolen datasets. The sample records across the listings include employee emails, phone numbers, job titles, full names, and workplace addresses.

“The impact for individuals is a heightened risk of social engineering attacks. Compromised credentials may be rotated by now, but in case it wasn’t it could be used for further data exfiltration,” said Cybernews researchers.

An attacker with accurate information about an organization’s employees, managers, departments, and reporting structures can construct highly convincing phishing messages. A criminal could, for example, impersonate an employee’s manager or an IT administrator and use real organizational details to make a request appear legitimate.

For more information, here’s the full article: https://cybernews.com/security/mcdonalds-vodafone-azure-microdoft-credential-theft/

UPDATE: Roman Sannikov, Global Research Coordinator, iCOUNTER Had This To Say:

“This isn’t a breach of Azure; it’s a breach of credential hygiene that happened to land on Azure tenants. TheHatman didn’t need to touch a vulnerability; infostealer malware harvested valid logins, and from there it’s a straight walk into the Entra directory. What should worry defenders more than the record counts is what’s actually in the data: service account names and global admin identities. That’s more of a target list than a list of victims. Hudson Rock called it a roadmap for social engineering, and they’re right: an attacker no longer has to guess who holds privileged access at McDonald’s or Vodafone; they have the org chart handed to them. The operational question for any threat intel team right now isn’t ‘were we on this list.’ It’s whether the same infostealer logs that fed this campaign already have your employees’ credentials sitting in a marketplace nobody’s checked yet.

There’s a second exposure most teams miss: any organization that does business with McDonald’s, TCS, Vodafone, HCL, or IHG should already be treating whatever data those companies hold on them as compromised and raising their security posture toward those specific relationships accordingly. This is exactly why knowing when your third parties are at risk of compromise, not just when you are, has to be part of the collection requirement. Once a threat actor is sitting inside an organization at this level, they have a direct pathway into every partner and vendor connected to it.”

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading