
Over the past few days, hackers have allegedly been offering sensitive corporate data belonging to several major companies for sale on underground channels. Among the organizations reportedly affected are McDonald’s and Vodafone, with employee-related information said to be included in the stolen datasets. According to an analysis by Hudson Rock, a cybersecurity and infostealer intelligence platform, the data may have been obtained through the theft of Azure cloud credentials and subsequently offered for sale by a hacker known as “TheHatman.”
According to information attributed to Hudson Rock and a source on Telegram, TheHatman claims to have obtained data from tenants using Microsoft’s Azure cloud services through a credential theft operation. The alleged dataset is extensive and reportedly contains information associated with millions of employee records across multiple global organizations.
The data reportedly includes approximately 1.7 million records linked to McDonald’s, around 800,000 records associated with Tata Consultancy Services (TCS), approximately 425,000 records connected to Vodafone, and about 250,000 records belonging to HCL Technologies. Other organizations allegedly affected include InterContinental Hotels Group, with more than 185,000 records; Kyndryl, with approximately 170,000; Gap Inc., with around 80,000; Hexaware Technologies, with about 20,000; and Wyndham Hotels, with approximately 9,000 records.
The alleged incident highlights the growing risks associated with cloud credentials. Credential theft commonly occurs through techniques such as phishing and vishing, in which attackers deceive employees into revealing usernames, passwords, multi-factor authentication (MFA) information, or session tokens. Once these credentials or tokens are obtained, attackers may be able to bypass security controls and gain unauthorized access to cloud environments and corporate resources.
Cloud platforms such as Azure are widely used by organizations to store and manage business applications, employee information, and other critical resources. As a result, compromised credentials can provide attackers with access to large amounts of information without necessarily requiring them to directly compromise an organization’s physical infrastructure.
Hudson Rock reportedly identified samples of the allegedly stolen information that included employee names, contact details, job titles, departments, designations, assignments, and information about direct reporting relationships. Such information can be particularly valuable to cybercriminals because it may be used for further targeted phishing, impersonation, business email compromise, or social-engineering attacks.
However, the claims surrounding the datasets should be treated with caution until the affected organizations or independent investigations formally confirm the extent and authenticity of the alleged breach. Nevertheless, the incident serves as another warning about the importance of protecting cloud identities, enforcing strong MFA, monitoring suspicious logins and session activity, and regularly reviewing access privileges.
As organizations continue moving critical operations to cloud platforms, compromised credentials remain one of the most significant entry points for cybercriminals. The alleged sale of employee data from major companies demonstrates how a single credential theft campaign can potentially expose information across multiple organizations and create further security risks.
Join our LinkedIn group Information Security Community!










