Millions of employee records have reportedly leaked online, and the companies which are involved in this alleged hack are the household names. A new report suggests that a hacker going by TheHatman is selling data online allegedly stolen from the Microsoft Azure systems of major firms. The companies that have been included in this alleged leak include McDonald’s, Gap Inc, Vodafone, HCL Technologies, InterContinental Hotels Group, Kyndryl, Tata Consultancy Services, Hexaware Technologies and Wyndham Hotels. The seller claims to hold more than 3.6 million records in total, which he gathered starting July 31st using compromised credentials. Reports also suggest that the biggest single file belongs to McDonald’s, with over 1.7 million employee records up for sale. Here’s everything we know about this alleged leak.
According to a report by BleepingComputer, the allegedly leaked data contains basic employee details, including full names, email addresses, phone numbers, job titles, and postal addresses. In addition, a listing on Kyndryl reportedly claims that the leaked data also includes service accounts and other internal tenant information. The hacker has shared sample files with potential buyers as proof that the data is genuine.
Also read: OpenAI president warns companies: AI-powered cyberattacks are coming, here are 10 steps to stay safe
Cybercrime intelligence firm Hudson Rock analysed the leaks and found the data contains foundational corporate directory attributes, including active domains and tenant-specific .onmicrosoft.com structures, along with service accounts and the names of global administrators, giving it high confidence the data is authentic, though the exact access and exfiltration method remain unknown. However, BleepingComputer itself noted that it was unable to independently verify whether the leaked information was authentic.
The companies who were allegedly hacked also included the Indian tech giant TCS. However, the company has told the National Stock Exchange that it found no credible evidence of a breach of its systems or customer environments. Moreover, they said that the details which are being circulated are at least four years old and cover only basic employee information and that they have had strong safeguards in place against password spray and MFA fatigue attacks for more than two years.
Gap Inc. also gave a similar response, stating that its preliminary investigation found no evidence of a breach and that the data are limited in scope, non-sensitive, and dated back several years.
Do note that BleepingComputer, in their report, cited that they had contacted all the listed companies about the alleged breach but had not received comments from most by the time of publication.
Also read: OnePlus 16 tipped to get bigger display, 9000mAh battery and high refresh rate: All details
Even if some of the data turns out to be outdated, experts say it could still be misused. Basic details like job titles, emails and phone numbers can help criminals craft convincing phishing messages or trick employees into sharing more sensitive information. Security researchers who studied the leak say the structure of the files looks authentic, even though the exact method used to steal the data is still unclear.
Not only that, but to keep such details protected and to ensure that similar incidents do not occur in the future, experts recommend using strong passwords with multi-factor authentication and regular monitoring of employee accounts.