Skip to main content
VodafoneSecurity incident

Massive Azure Breach Hits McDonald’s, Vodafone, TCS and More

What happened

A threat actor is selling an internal employee directory allegedly exfiltrated from Vodafone's Azure and Entra tenants.

Source

Article excerpt

Highlighted: the sentence this signal was extracted from

A threat actor known as TheHatman is selling internal employee directories allegedly exfiltrated from the Azure and Entra tenants of McDonald's, Vodafone, and seven other Fortune 500 companies, cybersecurity firm Hudson Rock reported this week. The McDonald's dataset alone totals more than 1.7 million records. TheHatman began flooding cybercrime forums with the directories over the past week, targeting nine companies across IT services, hospitality, telecommunications, retail, and logistics. Cybersecurity firm Hudson Rock reviewed the samples and found the corporate email addresses and field names match standard Azure directory exports. The seller says every dataset was downloaded straight from the victims' Azure and Entra tenants using stolen credentials. A massive data breach has exposed millions of records from Fortune 500 companies, including McDonald's and Vodafone, due to compromised Azure credentials. This incident underscores the critical need for robust credential management, multi-factor authentication, and vigilant… pic.twitter.com/EQkPatzvYA McDonald's tops the list by a wide margin. The full breakdown across all nine companies follows: TheHatman has not described the exact intrusion method beyond citing compromised credentials, and Hudson Rock calls the vector inconclusive. The access could trace to Infostealer malware harvesting session tokens, a successful...

Keep reading with a free account

The rest of this article, and every signal for Vodafone, is in your free account.

Extracted by Autobound

From the Signal API record
Event
Security incident

What this signalsA breach often leads to new security spend.

More security incident signals at other companies

The full record

From the Signal API record

Details

Issue named
internal employee directory exfiltrated from Azure and Entra tenants

Extraction

Confidence
90%
Detected
Aug 17, 2026
signal_type
news
signal_subtype
security_incident

Use this data

Get every security incident signal for Vodafone and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Vodafone this week?”

  2. Send it to your own tools

    The Signal API returns security incident signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full news record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/1fee3065-79c6-1728-af95-f1227a0e9cb3 returns this record as JSON. POST /v1/companies/enrich returns every signal for vodafone.com.

{
  "signal_id": "1fee3065-79c6-1728-af95-f1227a0e9cb3",
  "signal_type": "news",
  "signal_subtype": "security_incident",
  "detected_at": "2026-08-17T11:10:16+00:00",
  "company": {
    "name": "Vodafone",
    "domain": "vodafone.com"
  },
  "data": {
    "url": "https://sqmagazine.co.uk/?p=29989",
    "title": "Massive Azure Breach Hits McDonald’s, Vodafone, TCS and More - sqmagazine.co.uk",
    "excerpt": "A threat actor known as TheHatman is selling internal employee directories allegedly exfiltrated from the Azure and Entra tenants of McDonald’s, Vodafone, and seven other Fortune 500 companies, cybersecurity firm Hudson Rock reported this week. The McDonald’s dataset alone totals more than 1.7 million records. TheHatman began flooding cybercrime forums with the directories over the past week, targeting nine companies across IT services, hospitality, telecommunications, retail, and logistics. Cybersecurity firm Hudson Rock reviewed the samples and found the corporate email addresses and field names match standard Azure directory exports. The seller says every dataset was downloaded straight from the victims’ Azure and Entra tenants using stolen credentials. A massive data breach has exposed millions of records from Fortune 500 companies, including McDonald’s and Vodafone, due to compromised Azure credentials. This incident underscores the critical need for robust credential management, multi-factor authentication, and vigilant… pic.twitter.com/EQkPatzvYA McDonald’s tops the list by a wide margin. The full breakdown across all nine companies follows: TheHatman has not described the exact intrusion method beyond citing compromised credentials, and Hudson Rock calls the vector inconclusive. The access could trace to Infostealer malware harvesting session tokens, a successful...",
    "summary": "A threat actor is selling an internal employee directory allegedly exfiltrated from Vodafone's Azure and Entra tenants.",
    "planning": false,
    "image_url": "https://sqmagazine.co.uk/wp-content/uploads/2026/08/azure-data-breach-fortune-500-companies.jpg",
    "confidence": 0.9,
    "published_at": "2026-08-17T11:10:16Z",
    "vulnerability": "internal employee directory exfiltrated from Azure and Entra tenants",
    "article_sentence": "A threat actor known as TheHatman is selling internal employee directories allegedly exfiltrated from the Azure and Entra tenants of McDonald’s, Vodafone, and seven other Fortune 500 companies, cybersecurity firm Hudson Rock reported this week."
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.