GitLab bug can raise privileges

Published July 29, 2026

A cybercriminal stole millions of employee records from Microsoft Entra ID accounts at major companies like McDonald's and Vodafone. The data includes names, emails, phone numbers, and job roles.

Report priority
High
Targets
Microsoft Entra ID+7 more

How it works

  • A cybercriminal named TheHatman stole employee records by breaking into Microsoft Entra ID accounts at companies like McDonald's and Vodafone.
  • They then sold the data online.

What to do

Check if your company's name appears in the leaked datasets from McDonald's, Vodafone, or the other listed companies. If your work email or phone number is in the stolen data, your account may have been accessed.

If your company is listed, contact your IT or security team immediately. They should check for unauthorized access and reset compromised passwords. Microsoft Entra ID users should enable multi-factor authentication if not already enabled.

Technical details

Affected software: Microsoft Entra ID, McDonald’s Corporation, Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels Group, Kyndryl, Gap Inc

TheHatman broke into Microsoft Entra ID accounts at McDonald's and Vodafone. They downloaded employee records, names, emails, phone numbers, and job roles, then sold the data on cybercrime forums. Buyers got access to over 1.7 million McDonald's records and 425,000 Vodafone records.

A threat actor using the handle "TheHatman" claims to have stolen over 3.6 million employee directory records from Microsoft Entra ID environments of major companies, including McDonald's (1.7M records), Vodafone (425K), and Tata Consultancy Services (800K). The datasets, advertised on cybercrime forums between July 31 and mid-August, contain sensitive details like full names, email addresses (including .onmicrosoft.com accounts), phone numbers, job titles, manager hierarchies, and service account credentials. Hudson Rock assessed the data as likely authentic but noted unconfirmed extraction methods.

The theft appears linked to credential theft via infostealer malware, which steals saved browser sessions and tokens from infected systems. Exposed service accounts and global admin names pose a direct risk for follow-on attacks like phishing or privilege escalation. No confirmed zero-day flaw in Azure was identified.

References