Hacker claims millions of records stolen from corporate Azure tenants
Threat actor TheHatman claims millions of employee records stolen from Azure tenants of nine Fortune 500 firms, including McDonald's, Vodafone, Kyndryl, and TCS.
A threat actor known as TheHatman posted large internal employee directories on cybercrime forums over the past week, claiming each was pulled directly from the victim organization's Azure tenant. McDonald's tops the list at roughly 1.7 million records, followed by TCS (~800,000), Vodafone (~425,000), and HCL (~250,000), with IHG, Kyndryl, Gap, Hexaware, and Wyndham also named. Hudson Rock found samples consistent with standard Azure directory exports and suspects infostealer-derived credentials rather than a systemic Azure zero-day. TCS filed a statement with the Bombay Stock Exchange saying it found no credible evidence of a breach and the data appears over four years old.
Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs
Week in review: Medusa ransomware hit 500+ orgs per CISA, millions of Azure tenant records allegedly stolen, SafePal and French tax authority breaches disclosed.
Help Net Security's weekly roundup covers the FBI, CISA, and HHS joint advisory update reporting Medusa ransomware has breached more than 500 organizations since June 2021, and threat actor TheHatman's claim of millions of employee records stolen from Azure tenants of Fortune 500 firms including McDonald's, Vodafone, Kyndryl, and Tata Consultancy Services, per Hudson Rock. It also covers the SafePal breach affecting 39,798 customers, France's DGFiP breach exposing data on 678,000 individuals, and UT San delaying its fall semester after a cyberattack. Security items include critical unauthenticated GitLab flaw CVE-2026-19478, an actively exploited patched macOS Screen Sharing flaw deploying a cryptominer, US charges against 17 Mabna Institute Iranian hackers over 31TB of stolen academic data, and Google Mandiant's AI agents finding 100+ high-severity vulnerabilities.
Cybersecurity jobs available right now: December 16, 2025
Help Net Security rounds up open cybersecurity jobs at Grant Thornton, Central Bank of Ireland, Ford, Kraken, Docebo and others across multiple countries.
This is a job listing roundup covering cybersecurity openings at organizations including Grant Thornton, the Central Bank of Ireland, Ford Motor Company, Global Medical Response, banglalink, Mindrift, Kraken, PFH Technology Group, Kiwibank, Mazrui International, Docebo and Alpitronic. Roles span SOC operations, GRC, endpoint security, FedRAMP compliance, threat intelligence and privacy leadership across the USA, Ireland, India, Bangladesh, France, UAE, Canada and other locations. All listings were marked as no longer accepting applications at publication time.
McDonald’s Employee Data Appears in Leak, Seller Claims 1.7M Records Stolen
A seller offers 1.7 million McDonald's employee records allegedly taken from its Azure tenant via compromised credentials; an 8,000-row sample verifies as genuine.
A forum seller named TheHatman posted an 8,000-row sample of McDonald's employee directory data, claiming a 1.7 million-record haul pulled directly from the company's Azure tenant using compromised credentials. Ransomnews analysis found authentic Entra ID export artifacts, including genuine domains, tenant-internal addresses, encoding errors, and truncated HR fields, but could not verify the data's age or the 1.7 million figure. The same seller listed nine datasets in 16 days covering about 3.6 million records across McDonald's, Vodafone, Gap, hotels, and IT outsourcers, suggesting infostealer-driven credential resale. No passwords or hashes appear in the sample, so the primary risk is social engineering.