Hacker working showing employee databases data breach

Employee Databases from Multiple Fortune 500 Companies Affecting 3.6 Million Employees Listed on the Dark Web

Employee databases of multiple Fortune 500 companies are listed for sale on multiple dark web forums after a threat actor identifying as “TheHatman” allegedly compromised Microsoft Azure infrastructure using stolen credentials.

“I’m selling McDonald’s Corporation internal employee dump downloaded directly from Azure Tenant using compromised credentials,” the threat actor stated.

Several Fortune 500 companies have acknowledged the employee data breach but downplayed the impact, saying it affected basic information that was several years old.

Hackers breach multiple Fortune 500 companies’ employee databases

The employee database breach affected several Fortune 500 companies, including Gap Inc., Hexaware, HCL Technologies, InterContinental Hotel Group (IHG), Kyndryl, McDonald’s, Tata Consultancy Services (TCS), and Vodafone.

The threat actor claims the breached employee databases contain 3.64 million data records, including 1.7 million employee records from McDonald’s and 800,000 records from Tata Consultancy Services. The attackers also exfiltrated 425,000 records from Vodafone, 250,000 records from HCL, and 185,000 from IHG.  The hacker has provided samples of the compromised employee databases as proof.

While information varied by organization, the employee databases exposed workers’ names, addresses, phone numbers, postal addresses, employee IDs, job titles, service accounts, and tenant information.

“This campaign is a reminder that threat actors do not need to break into Azure itself, they just need one set of working credentials, said Max Gannon, Cyber Intelligence Team Manager at Cofense. “The password spraying and MFA fatigue techniques the threat actor claims to have used are old techniques, but they still work because the payoff is enormous. A single compromised login can hand over an entire employee directory, including the accounts of global administrators, which gives threat actors a roadmap for their next round of spearphishing.”

Meanwhile, Tata Consultancy has acknowledged the data breach, but downplayed the impact, saying that the data was at least 4 years old and contained basic employee information.

“The information referenced appears to be more than four years old and limited to basic employee information. There is no indication that customer data, customer systems, or TCS operational systems have been impacted,” the company said in a regulatory filing with the National Stock Exchange of India.

TCS confirmed that the attacker used password spraying and Multi-Factor Authentication (MFA) fatigue to gain initial access. The company also said it had implemented strong authentication requirements two years before the alleged data breach and that its security controls were effective at the time of the attack. Gap Inc. also downplayed the incident, claiming that the alleged data breach was limited in scope and the leaked data was non-sensitive and several years old.

While the leaked data was dated, cybercriminals could still use it to target affected victims with follow-on spear phishing attacks, luring them into disclosing sensitive details such as credit card information or executing business email compromise (BEC) attacks.

“Even years old employee data, names, titles, phone numbers, and internal account structure, is valuable to threat actors because it makes future phishing emails look internally accurate and hard to question,” added Gannon. “Organizations should treat this less as a one time breach story and more as a warning that credential hygiene and MFA resistant to fatigue attacks remain foundational, not optional.”

Similarly, threat intelligence firm Hudson Rock analyzed the data from the compromised employee databases and found it consistent with “active domains and tenant-specific .onmicrosoft.com structures.” Hudson Rock assessed that the data included core identity and contact details, organizational structures, and access and group mappings. According to Hudson Rock, the exploited vector also aligned with social engineering and spearphishing attacks. Hudson Rock also ruled out a zero-day exploitation and suggested an active infostealer was likely deployed.

“While we don’t have definitive confirmation as to which specific credentials were used to hack these organizations, Hudson Rock researchers were able to find compromised Azure credentials originating from Infostealer infections linked to most of the affected companies,” the firm explained.

Cloud infrastructure is a fertile hunting ground for cybercriminals

Opportunistic and highly skilled hackers, including state-sponsored actors, constantly attack cloud infrastructure.

In 2024, hacking group ShinyHunters breached Snowflake’s cloud environment using stolen credentials and compromised approximately 165 organizations, including Lending Tree, Santander, Neiman Marcus, and TicketMaster.

In 2025, Google Threat Intelligence documented threat actors exploiting cloud misconfigurations and weak or missing credentials to compromise Google Cloud environments.

In the same year, Microsoft Threat Intelligence detected Storm-2949 exfiltrating data from an organization’s Microsoft 365 applications and Azure-hosted production environments using Azure management features.

In 2026, hackers exfiltrated the personal information of approximately 3.65 million individuals after compromising the CareCloud AWS environment for several days.