A seller on a data-trading forum has listed what they describe as an internal McDonald’s employee directory, claiming more than 1.7 million records pulled from the company’s Azure tenant using compromised credentials. Ransomnews analysed the 8,000-row sample the seller published on 16 August 2026. The sample is consistent with a genuine Entra ID directory export. McDonald’s has not commented, and the same account has listed eight other companies the same way since 1 August.
What is actually being offered
The listing is a straightforward private sale, posted at 4:08 AM forum time under the title “McDonalds 1.7M+ Azure Internal Employee Dump”. The seller, an account called TheHatman, writes that the data was “downloaded directly from Azure Tenant using compromised credentials” and that it contains “employee accounts, service accounts, and other tenant account records”. No price is named. Buyers are invited to make offers.
To evidence the claim, the seller attached a free 8,000-record sample. That file is the entire basis for what follows. Ransomnews analysed it offline. We did not access, probe or authenticate against any McDonald’s system, and we have redacted the sample’s download location from the screenshot below because it still resolves to real people’s contact details.

The sample is a tab-separated file with 19 columns. The column names matter more than they look: FacsimileTelephoneNumber, PhysicalDeliveryOfficeName and UsageLocation are not names anybody invents. They are the property names returned by Microsoft’s older directory tooling, the Get-MsolUser and Get-AzureADUser PowerShell commands that administrators have used to pull user lists out of Azure AD, now Entra ID, for the better part of a decade. Whoever produced this file ran one of those commands and piped it to Export-Csv.
Is the alleged McDonald’s data genuine?
Everything testable in the sample points to a real directory export from McDonald’s own tenant. We ran the checks we would run on any listing, and the file passed all of them.
Every email domain belongs to McDonald’s. The sample contains 50 distinct domains and all 50 are McDonald’s-controlled. The spread itself is the tell. Corporate staff sit on us.mcd.com and uk.mcd.com. Restaurant crew sit on crew.mcd.com and external.mcd.com. Individual restaurants have their own mailboxes on us.stores.mcd.com, au.stores.mcd.com and nz.stores.mcd.com. Franchisees appear on franchisee.pl.mcd.com and au.licensee.mcd.com. There are national variants for France, Canada, Taiwan, Brunei, Malta and thirty other markets. A marketing list assembled from LinkedIn would show none of this structure.
The file carries the tenant’s own Microsoft address. Three rows use mcdonaldscorp.onmicrosoft.com. Every Microsoft 365 tenant gets one of these built-in addresses when it is created, and it is normally invisible from outside. A handful more use waad.mcd.com, an internal domain whose name is an abbreviation of Windows Azure Active Directory. Neither address is something an outsider could guess or scrape. They are what you see when you are reading the directory from the inside.
The file is broken in the ways real exports are broken. 233 rows contain mangled characters: Königswinter appears as “Königswinter”, München as “München”, and Ukrainian job titles are rendered as unreadable strings of Cyrillic run through the wrong character set. This is what happens when somebody runs Export-Csv without specifying UTF-8 encoding. It’s a mistake, and it is not the kind of mistake anybody makes on purpose. A fabricated dataset doesn’t come with authentic encoding damage.
The job titles carry the fingerprint of an HR system. 85 titles in the sample stop dead at exactly 30 characters, mid-word: DIR-ENTERPRISE CHANGE MANAGEME, MGR-CYBERSECURITY SERVICE DEPL, FIELD ADMINISTRATION COORDINAT. That is a fixed-width field in an HR platform bleeding through into the directory during a sync. The truncation only affects the uppercase US corporate feed, though. Other markets run long, because different regions run different HR systems and they sync on different rules.
Then there is the vocabulary. Titles reference McOpCo, McDonald’s own term for company-operated restaurants, alongside GTIO and an “IOM BU” reference that maps to International Operated Markets, one of the segments the company actually reports on. There are entries for a shift manager trainee, a “PRIMARY MAIN. PERSON” and, in 120 rows, a “BACKUP MAINTAINENCE PERSON”, spelling error and all. Nobody generating fake data introduces a typo into a job title.
Only one part of the file can be checked against the outside world, and it holds. The sample includes restaurant mailboxes with street addresses and phone numbers. The entry for [email protected], listed as “556 Upton” at “UPTON BY PASS, UPTON, WIRRAL, CH49 6QG” with the number +441516781733, matches the publicly listed McDonald’s at Upton By-Pass, Birkenhead, on 0151 678 1733. That’s one confirmation, not a hundred, but it is a real-world anchor the rest of the file has to be consistent with.
The guest accounts name real partners. Where the CompanyName field is populated, it lists HAVI, McDonald’s actual global supply-chain partner, alongside Capgemini, Accenture, Cognizant, Fujitsu, Sopra Steria, McKinsey and Boston Consulting Group. Sitting beside them are franchisee entities with names like Chirp Foods Inc. and Entreprises Vana Inc. This is what a large enterprise directory looks like once contractors and franchise operators have been given guest access, and it is a level of texture that would take real effort to invent.
Internal consistency holds up too. Of the 8,000 rows, 7,998 carry a login address and every single one is unique, with no duplicate accounts anywhere in the file. Country agrees with the Microsoft licensing location in 99.7% of rows, and the international dialling code on the phone number agrees with it in 95.5%. Field completeness is patchy in the way real directories are patchy: 64.3% have a mail address, 13.9% have a mobile number, 1.7% have a postcode. Generated data tends to be either complete or randomly sparse. Real data is unevenly sparse, and this is unevenly sparse in a way that tracks which market each account belongs to.
What the sample cannot tell us
The file contains no dates at all. There’s no creation date, no last-login, and nothing else that would let you age a single row. This is the single most important limitation on the story and it should temper how anyone reads the listing. We can say with confidence that the data came out of McDonald’s directory. We cannot say from the file alone when it came out.
The only dating handle available is McDonald’s own market footprint. There is not a single Russian record in the sample, and not a single Kazakh one. McDonald’s sold its Russian business in May 2022 and exited Kazakhstan in January 2023, where the restaurants reopened under the unrelated “I’m” brand. Ukraine, by contrast, is present with 94 records. Taken together that places the export somewhere in 2023 or later. That is a wide window, and it is not the same thing as saying the data is current.
The 1.7 million figure is also untested. 8,000 records is 0.47% of the claim. What the sample does establish is that the number is not absurd on its face: 89.4% of the sample sits on restaurant-side domains, so if that ratio holds, the bulk of any full dataset would be crew and store staff rather than corporate employees. McDonald’s system employs well over a million people worldwide, and the existence of crew.mcd.com and external.mcd.com shows that restaurant-level staff do receive tenant accounts. Plausible is not the same as verified.
Finally, the method is the seller’s word. “Compromised credentials” is their description of how the data left, not something visible in a CSV file. Only McDonald’s can establish what actually happened, and the company has not commented.
This is not a McDonald’s story alone
The McDonald’s listing was one of three the seller posted in under three hours. Vodafone went up at 2:16 AM with 425,000 records claimed, McDonald’s followed at 4:08 AM, and Gap Inc. went up at 5:09 AM with 80,000. All three use the same sentence to describe the source, the same field list and the same offer structure. Widen the view to the account’s full posting history and the pattern gets starker.

TheHatman has posted nine times since the account was registered in April 2026, and all nine posts are listings of this kind. Ransomnews reviewed the account’s full thread history. It runs from 1 to 16 August 2026: Hexaware Technologies and Kyndryl on 1 August, Wyndham Hotels and InterContinental Hotels on 2 August, HCL Technologies on 7 August, Tata Consultancy Services on 10 August, then Vodafone, McDonald’s and Gap Inc. in the small hours of 16 August. Together the nine listings claim roughly 3.64 million records.


The earlier posts word it slightly differently, saying the data came “directly from Azure/Entra portal using compromised credentials” where the 16 August batch says “from Azure Tenant”. The substance does not change. Same claimed source, same field list, same private-sale format.
Four of the nine are IT services and outsourcing firms. Hexaware, Kyndryl, HCL Technologies and Tata Consultancy Services are not retailers or hotel chains. They are companies that run other companies’ infrastructure, and between them those four listings account for 1.24 million of the claimed records. If directory data from that tier of supplier is genuinely circulating, the exposure doesn’t stop at their own staff, because the people in those directories are often the named administrators on their clients’ systems.
That pattern cuts in an interesting direction. The instinct on seeing an account with nine posts and zero reputation claim nine corporate directories in a fortnight is to assume fabrication. The evidence points the other way. If someone were inventing nine datasets, they would have no reason to give them all the same 19-column schema, because each victim’s data would be invented separately. An identical schema across unrelated victims is what you get when one person runs one export script against whatever tenant they currently hold credentials for. The seller is not a breach specialist. They are running a volume trade, and the tool is doing the work.

It cuts the other way on the numbers, though. A seller working through nine listings in a fortnight has every incentive to round up, and nothing in a free sample constrains what they write in the headline. Treat the 1.7 million as marketing until somebody demonstrates otherwise.
How this kind of access usually happens
Reading a directory does not require a sophisticated intrusion. It requires one working account and a tenant that lets ordinary users enumerate other users, which is the default in Entra ID unless an administrator has explicitly restricted it. From there, a single PowerShell command returns every user object the account can see, and the schema in this sample is exactly what that command returns.
Where the credentials come from is rarely mysterious. Infostealer malware harvests saved browser credentials by the million and feeds a resale market that initial access brokers have industrialised. In January 2026, Hudson Rock documented a single actor who compromised roughly 50 organisations worldwide on exactly this basis, using credentials lifted by RedLine, Lumma and Vidar. As the researchers put it, because the organisations did not enforce multi-factor authentication, “the attacker walks right in through the front door”.
That is the shape this campaign has. One operator, one playbook, and a queue of tenants where a stolen password was enough. It is worth being precise about what that means: none of these nine companies has confirmed anything, and a listing is not a breach notification. But the technique described in the listings is neither exotic nor implausible, and it is the most common way large directories end up on sale.
What McDonald’s staff and franchisees should do now
Treat this as a phishing and social-engineering problem rather than an account-takeover one. There’s nothing in the sample you could log in with. No passwords, no hashes, and no national identifiers or payment data either. What it does contain is close to an ideal targeting package: full names, job titles, departments, reporting locations, internal email conventions across 50 domains, employee ID formats that differ by market, and direct phone numbers for both people and individual restaurants.
- Expect helpdesk impersonation. Somebody holding this data can call a restaurant, name the general manager, quote their employee ID and ask for a password reset. Verification procedures that rely on knowing internal details are no longer adequate.
- Watch for franchise-level invoice fraud. The sample identifies franchisee entities and the vendor contacts attached to them. That is the raw material for business email compromise aimed at operators rather than head office.
- Enforce phishing-resistant MFA everywhere, including crew accounts. Restaurant-side accounts make up nearly 90% of the sample and are the ones most likely to sit outside a conditional-access policy.
- Restrict directory enumeration. Limiting default user read permissions removes the ability for one compromised account to list everyone else in the tenant.
- Review guest and contractor accounts. The sample shows vendor staff from at least a dozen consultancies holding tenant identities. Each one is a route in, and each one is somebody else’s security posture.
For individuals named in the data, there is no action that removes the exposure. The realistic response is scepticism about unsolicited contact that arrives already knowing your role and your store, and a refusal to act on instructions that arrive by phone or email without out-of-band confirmation.
What this means for anyone running an Entra tenant
The employee directory is an underrated asset and most organisations do not treat it as one. It isn’t classified, it holds no secrets, and it’s readable by default to every account in the tenant. It is also a complete organisational map, and in the hands of somebody building a social-engineering campaign it is worth considerably more than a list of email addresses.
The uncomfortable part of this story is how little was required. There’s no zero-day here. No clever lateral movement either, and no ransomware. Somebody had a valid credential, ran a command that Microsoft ships in the box, and walked out with the org chart. Nine times, across sixteen days, at nine different companies. Our read is that directory enumeration is the most under-defended surface in the average Microsoft 365 estate, precisely because nothing about it looks like an attack in the logs.
Ransomnews has contacted McDonald’s for comment and will update this article with any response. We track live extortion and leak-site activity on the Ransomtracker, and our recent verification work includes the Chess.com dataset and the Żabka supplier-account breach.
Frequently asked questions
Has McDonald’s confirmed a data breach?
No. McDonald’s has not commented on the listing and has issued no breach notification. Everything in the listing is the seller’s claim. What Ransomnews independently established is that the published sample is consistent with a genuine export from McDonald’s Entra ID directory.
Is customer data affected?
Not in the sample. The 8,000 records reviewed contain only workforce data: names, work emails, job titles, employee IDs, work phone numbers and office or restaurant addresses. There are no customer records, no payment details and no passwords of any kind.
Is this the same as the McHire breach in 2025?
No. The 2025 incident involved Paradox.ai’s McHire recruitment chatbot and exposed data belonging to job applicants. This listing concerns the internal employee directory and comes from a different source entirely.
How old is the alleged McDonald’s data?
It cannot be dated precisely. The file contains no timestamps of any kind. The absence of Russian and Kazakh records, combined with the presence of Ukrainian ones, places the export somewhere in 2023 or later, which is a wide window rather than an answer.
Are 1.7 million records really for sale?
Unverified. The published sample is 8,000 records, which is 0.47% of the claimed total. The ratio of restaurant staff to corporate staff in the sample makes a figure of that order plausible for a company of McDonald’s size, but nothing in the sample proves the seller holds it.
Which other companies are named in the same campaign?
Eight others. The same account listed Hexaware Technologies, Kyndryl, Wyndham Hotels, InterContinental Hotels, HCL Technologies, Tata Consultancy Services, Vodafone and Gap Inc. between 1 and 16 August 2026. None of the nine organisations has confirmed anything.
How can an organisation stop this happening to its own directory?
Enforce phishing-resistant multi-factor authentication on every account including frontline staff, restrict default user permissions so ordinary accounts cannot enumerate the whole directory, and monitor for bulk Microsoft Graph read activity. Directory enumeration by a valid account generates almost no signal unless you are looking for it.
Sources and further reading
- The Register, One criminal, 50 hacked organizations, and all because MFA wasn’t turned on
- CSO Online, McDonald’s AI hiring tool’s password ‘123456’ exposed data of 64M applicants (unrelated 2025 incident, included for context)
- Ransomnews, Initial access brokers and the ransomware supply chain
The Ransomnews Monthly
One email a month. Original leak-site data, victim census updates, and the findings that did not make the articles. No spam, unsubscribe any time.
Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.
