Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • Newsletter
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • Newsletter
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Cybercrime

McDonald’s employee data listed for sale in wider Entra campaign

Neringa MacijauskaitėBy Neringa MacijauskaitėAugust 16, 2026Updated:August 16, 2026No Comments17 Mins Read236 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Golden arches rendered out of rows of directory records, over the headline Employee directory, listed for sale
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

A seller on a data-trading forum has listed what they describe as an internal McDonald’s employee directory, claiming more than 1.7 million records pulled from the company’s Azure tenant using compromised credentials. Ransomnews analysed the 8,000-row sample the seller published on 16 August 2026. The sample is consistent with a genuine Entra ID directory export. McDonald’s has not commented, and the same account has listed eight other companies the same way since 1 August.

// KEY FACTS

Threat actor
TheHatman (data-trading forum seller)
Victim
McDonald's Corporation · Quick-service restaurants · United States (global tenant, 50 market domains in the sample)
Timeline
Attack: Not established. The file contains no date fields of any kind  ·  Disclosed: 2026-08-16
Data claimed
Seller claims over 1,700,000 records. Ransomnews reviewed the published 8,000-row sample, which is 0.47% of the claim · Display names, corporate and restaurant email addresses, employee IDs, job titles, departments, work and mobile numbers, office locations and street addresses, covering corporate staff, restaurant crew, franchisee employees, vendor guest accounts and shared mailboxes. No passwords, hashes or payment data
Ransom status
Offered for private sale. No asking price published, seller invites offers
Verification
Ransomnews Research Team analysed the seller's own sample offline. All 50 email domains in it are McDonald's-controlled, including the tenant's built-in mcdonaldscorp.onmicrosoft.com address. Schema, encoding damage and field truncation are all consistent with a PowerShell export from Entra ID. McDonald's has not commented and the 1.7 million figure remains unverified

What is actually being offered

The listing is a straightforward private sale, posted at 4:08 AM forum time under the title “McDonalds 1.7M+ Azure Internal Employee Dump”. The seller, an account called TheHatman, writes that the data was “downloaded directly from Azure Tenant using compromised credentials” and that it contains “employee accounts, service accounts, and other tenant account records”. No price is named. Buyers are invited to make offers.

To evidence the claim, the seller attached a free 8,000-record sample. That file is the entire basis for what follows. Ransomnews analysed it offline. We did not access, probe or authenticate against any McDonald’s system, and we have redacted the sample’s download location from the screenshot below because it still resolves to real people’s contact details.

Forum thread by TheHatman advertising 1.7 million McDonald's employee records allegedly taken from the company's Azure tenant, with the sample file URL redacted
The alleged McDonald’s listing. The sample download URL has been redacted by Ransomnews.

The sample is a tab-separated file with 19 columns. The column names matter more than they look: FacsimileTelephoneNumber, PhysicalDeliveryOfficeName and UsageLocation are not names anybody invents. They are the property names returned by Microsoft’s older directory tooling, the Get-MsolUser and Get-AzureADUser PowerShell commands that administrators have used to pull user lists out of Azure AD, now Entra ID, for the better part of a decade. Whoever produced this file ran one of those commands and piped it to Export-Csv.

Is the alleged McDonald’s data genuine?

Everything testable in the sample points to a real directory export from McDonald’s own tenant. We ran the checks we would run on any listing, and the file passed all of them.

// WHAT THE 8,000-ROW SAMPLE SETTLES Ransomnews Research Team, offline analysis of the seller’s own sample file. No McDonald’s system was accessed. Consistent with a genuine directory export 50 / 50 email domains McDonald’s-controlled 7,998 unique logins out of 8,000 rows 99.7% country matches licence location 95.5% phone dialling code matches location 233 rows with PowerShell encoding damage 85 job titles cut at exactly 30 characters 1 UK store row matched to a public listing What the sample cannot settle 0 date fields anywhere in the schema the file cannot be dated from its own contents 0.47% of the claimed total was published 8,000 rows cannot test a 1.7 million claim n/a the stated method is unverified only McDonald’s can confirm how the data left 0 passwords, hashes or payment fields no customer data of any kind in the sample // THE DECIDING DETAIL Three rows carry the address mcdonaldscorp.onmicrosoft.com, the tenant’s built-in Microsoft domain. That address is visible from inside the directory. It is not something a scraper or a marketing database would ever hold.

Every email domain belongs to McDonald’s. The sample contains 50 distinct domains and all 50 are McDonald’s-controlled. The spread itself is the tell. Corporate staff sit on us.mcd.com and uk.mcd.com. Restaurant crew sit on crew.mcd.com and external.mcd.com. Individual restaurants have their own mailboxes on us.stores.mcd.com, au.stores.mcd.com and nz.stores.mcd.com. Franchisees appear on franchisee.pl.mcd.com and au.licensee.mcd.com. There are national variants for France, Canada, Taiwan, Brunei, Malta and thirty other markets. A marketing list assembled from LinkedIn would show none of this structure.

The file carries the tenant’s own Microsoft address. Three rows use mcdonaldscorp.onmicrosoft.com. Every Microsoft 365 tenant gets one of these built-in addresses when it is created, and it is normally invisible from outside. A handful more use waad.mcd.com, an internal domain whose name is an abbreviation of Windows Azure Active Directory. Neither address is something an outsider could guess or scrape. They are what you see when you are reading the directory from the inside.

The file is broken in the ways real exports are broken. 233 rows contain mangled characters: Königswinter appears as “Königswinter”, München as “München”, and Ukrainian job titles are rendered as unreadable strings of Cyrillic run through the wrong character set. This is what happens when somebody runs Export-Csv without specifying UTF-8 encoding. It’s a mistake, and it is not the kind of mistake anybody makes on purpose. A fabricated dataset doesn’t come with authentic encoding damage.

The job titles carry the fingerprint of an HR system. 85 titles in the sample stop dead at exactly 30 characters, mid-word: DIR-ENTERPRISE CHANGE MANAGEME, MGR-CYBERSECURITY SERVICE DEPL, FIELD ADMINISTRATION COORDINAT. That is a fixed-width field in an HR platform bleeding through into the directory during a sync. The truncation only affects the uppercase US corporate feed, though. Other markets run long, because different regions run different HR systems and they sync on different rules.

Then there is the vocabulary. Titles reference McOpCo, McDonald’s own term for company-operated restaurants, alongside GTIO and an “IOM BU” reference that maps to International Operated Markets, one of the segments the company actually reports on. There are entries for a shift manager trainee, a “PRIMARY MAIN. PERSON” and, in 120 rows, a “BACKUP MAINTAINENCE PERSON”, spelling error and all. Nobody generating fake data introduces a typo into a job title.

Only one part of the file can be checked against the outside world, and it holds. The sample includes restaurant mailboxes with street addresses and phone numbers. The entry for [email protected], listed as “556 Upton” at “UPTON BY PASS, UPTON, WIRRAL, CH49 6QG” with the number +441516781733, matches the publicly listed McDonald’s at Upton By-Pass, Birkenhead, on 0151 678 1733. That’s one confirmation, not a hundred, but it is a real-world anchor the rest of the file has to be consistent with.

The guest accounts name real partners. Where the CompanyName field is populated, it lists HAVI, McDonald’s actual global supply-chain partner, alongside Capgemini, Accenture, Cognizant, Fujitsu, Sopra Steria, McKinsey and Boston Consulting Group. Sitting beside them are franchisee entities with names like Chirp Foods Inc. and Entreprises Vana Inc. This is what a large enterprise directory looks like once contractors and franchise operators have been given guest access, and it is a level of texture that would take real effort to invent.

Internal consistency holds up too. Of the 8,000 rows, 7,998 carry a login address and every single one is unique, with no duplicate accounts anywhere in the file. Country agrees with the Microsoft licensing location in 99.7% of rows, and the international dialling code on the phone number agrees with it in 95.5%. Field completeness is patchy in the way real directories are patchy: 64.3% have a mail address, 13.9% have a mobile number, 1.7% have a postcode. Generated data tends to be either complete or randomly sparse. Real data is unevenly sparse, and this is unevenly sparse in a way that tracks which market each account belongs to.

What the sample cannot tell us

The file contains no dates at all. There’s no creation date, no last-login, and nothing else that would let you age a single row. This is the single most important limitation on the story and it should temper how anyone reads the listing. We can say with confidence that the data came out of McDonald’s directory. We cannot say from the file alone when it came out.

The only dating handle available is McDonald’s own market footprint. There is not a single Russian record in the sample, and not a single Kazakh one. McDonald’s sold its Russian business in May 2022 and exited Kazakhstan in January 2023, where the restaurants reopened under the unrelated “I’m” brand. Ukraine, by contrast, is present with 94 records. Taken together that places the export somewhere in 2023 or later. That is a wide window, and it is not the same thing as saying the data is current.

The 1.7 million figure is also untested. 8,000 records is 0.47% of the claim. What the sample does establish is that the number is not absurd on its face: 89.4% of the sample sits on restaurant-side domains, so if that ratio holds, the bulk of any full dataset would be crew and store staff rather than corporate employees. McDonald’s system employs well over a million people worldwide, and the existence of crew.mcd.com and external.mcd.com shows that restaurant-level staff do receive tenant accounts. Plausible is not the same as verified.

Finally, the method is the seller’s word. “Compromised credentials” is their description of how the data left, not something visible in a CSV file. Only McDonald’s can establish what actually happened, and the company has not commented.

This is not a McDonald’s story alone

The McDonald’s listing was one of three the seller posted in under three hours. Vodafone went up at 2:16 AM with 425,000 records claimed, McDonald’s followed at 4:08 AM, and Gap Inc. went up at 5:09 AM with 80,000. All three use the same sentence to describe the source, the same field list and the same offer structure. Widen the view to the account’s full posting history and the pattern gets starker.

// NINE LISTINGS, SIXTEEN DAYS, ONE ACCOUNT Every thread posted by «TheHatman». The account has made nine posts in total, and all nine are these. DATE ORGANISATION RECORDS CLAIMED 1 Aug Hexaware Technologies IT SERVICES 20,000 1 Aug Kyndryl IT SERVICES 170,000 2 Aug Wyndham Hotels 9,000 2 Aug InterContinental Hotels 185,000 7 Aug HCL Technologies IT SERVICES 250,000 10 Aug Tata Consultancy Services IT SERVICES 800,000 16 Aug Vodafone 425,000 16 Aug McDonald’s 1,700,000 16 Aug Gap Inc. 80,000 3,639,000 records claimed across all nine listings none of it verified beyond the McDonald’s sample 4 of 9 are IT services and outsourcing firms firms that hold access into their clients’ environments
Forum activity feed showing Gap, McDonald's and Vodafone employee directory listings posted by the same account within three hours
Three brands, three hours, one account. The wording is identical across all three listings.

TheHatman has posted nine times since the account was registered in April 2026, and all nine posts are listings of this kind. Ransomnews reviewed the account’s full thread history. It runs from 1 to 16 August 2026: Hexaware Technologies and Kyndryl on 1 August, Wyndham Hotels and InterContinental Hotels on 2 August, HCL Technologies on 7 August, Tata Consultancy Services on 10 August, then Vodafone, McDonald’s and Gap Inc. in the small hours of 16 August. Together the nine listings claim roughly 3.64 million records.

Forum thread history showing the same seller listing Tata Consultancy Services, HCL Technologies, InterContinental Hotels and Wyndham Hotels employee directories
Earlier threads from the same account: Tata Consultancy Services, HCL Technologies, InterContinental Hotels and Wyndham Hotels.
Forum thread history showing the same seller listing Hexaware Technologies and Kyndryl employee directories on 1 August 2026
The two oldest listings, both posted on 1 August: Hexaware Technologies and Kyndryl.

The earlier posts word it slightly differently, saying the data came “directly from Azure/Entra portal using compromised credentials” where the 16 August batch says “from Azure Tenant”. The substance does not change. Same claimed source, same field list, same private-sale format.

Four of the nine are IT services and outsourcing firms. Hexaware, Kyndryl, HCL Technologies and Tata Consultancy Services are not retailers or hotel chains. They are companies that run other companies’ infrastructure, and between them those four listings account for 1.24 million of the claimed records. If directory data from that tier of supplier is genuinely circulating, the exposure doesn’t stop at their own staff, because the people in those directories are often the named administrators on their clients’ systems.

That pattern cuts in an interesting direction. The instinct on seeing an account with nine posts and zero reputation claim nine corporate directories in a fortnight is to assume fabrication. The evidence points the other way. If someone were inventing nine datasets, they would have no reason to give them all the same 19-column schema, because each victim’s data would be invented separately. An identical schema across unrelated victims is what you get when one person runs one export script against whatever tenant they currently hold credentials for. The seller is not a breach specialist. They are running a volume trade, and the tool is doing the work.

Forum profile for the account TheHatman showing registration in April 2026, nine messages and a reputation score of zero
The seller’s profile: registered April 2026, nine posts, zero reputation. Thin history, high-value claims.

It cuts the other way on the numbers, though. A seller working through nine listings in a fortnight has every incentive to round up, and nothing in a free sample constrains what they write in the headline. Treat the 1.7 million as marketing until somebody demonstrates otherwise.

How this kind of access usually happens

Reading a directory does not require a sophisticated intrusion. It requires one working account and a tenant that lets ordinary users enumerate other users, which is the default in Entra ID unless an administrator has explicitly restricted it. From there, a single PowerShell command returns every user object the account can see, and the schema in this sample is exactly what that command returns.

Where the credentials come from is rarely mysterious. Infostealer malware harvests saved browser credentials by the million and feeds a resale market that initial access brokers have industrialised. In January 2026, Hudson Rock documented a single actor who compromised roughly 50 organisations worldwide on exactly this basis, using credentials lifted by RedLine, Lumma and Vidar. As the researchers put it, because the organisations did not enforce multi-factor authentication, “the attacker walks right in through the front door”.

That is the shape this campaign has. One operator, one playbook, and a queue of tenants where a stolen password was enough. It is worth being precise about what that means: none of these nine companies has confirmed anything, and a listing is not a breach notification. But the technique described in the listings is neither exotic nor implausible, and it is the most common way large directories end up on sale.

What McDonald’s staff and franchisees should do now

Treat this as a phishing and social-engineering problem rather than an account-takeover one. There’s nothing in the sample you could log in with. No passwords, no hashes, and no national identifiers or payment data either. What it does contain is close to an ideal targeting package: full names, job titles, departments, reporting locations, internal email conventions across 50 domains, employee ID formats that differ by market, and direct phone numbers for both people and individual restaurants.

  • Expect helpdesk impersonation. Somebody holding this data can call a restaurant, name the general manager, quote their employee ID and ask for a password reset. Verification procedures that rely on knowing internal details are no longer adequate.
  • Watch for franchise-level invoice fraud. The sample identifies franchisee entities and the vendor contacts attached to them. That is the raw material for business email compromise aimed at operators rather than head office.
  • Enforce phishing-resistant MFA everywhere, including crew accounts. Restaurant-side accounts make up nearly 90% of the sample and are the ones most likely to sit outside a conditional-access policy.
  • Restrict directory enumeration. Limiting default user read permissions removes the ability for one compromised account to list everyone else in the tenant.
  • Review guest and contractor accounts. The sample shows vendor staff from at least a dozen consultancies holding tenant identities. Each one is a route in, and each one is somebody else’s security posture.

For individuals named in the data, there is no action that removes the exposure. The realistic response is scepticism about unsolicited contact that arrives already knowing your role and your store, and a refusal to act on instructions that arrive by phone or email without out-of-band confirmation.

What this means for anyone running an Entra tenant

The employee directory is an underrated asset and most organisations do not treat it as one. It isn’t classified, it holds no secrets, and it’s readable by default to every account in the tenant. It is also a complete organisational map, and in the hands of somebody building a social-engineering campaign it is worth considerably more than a list of email addresses.

The uncomfortable part of this story is how little was required. There’s no zero-day here. No clever lateral movement either, and no ransomware. Somebody had a valid credential, ran a command that Microsoft ships in the box, and walked out with the org chart. Nine times, across sixteen days, at nine different companies. Our read is that directory enumeration is the most under-defended surface in the average Microsoft 365 estate, precisely because nothing about it looks like an attack in the logs.

Ransomnews has contacted McDonald’s for comment and will update this article with any response. We track live extortion and leak-site activity on the Ransomtracker, and our recent verification work includes the Chess.com dataset and the Żabka supplier-account breach.

Frequently asked questions

Has McDonald’s confirmed a data breach?

No. McDonald’s has not commented on the listing and has issued no breach notification. Everything in the listing is the seller’s claim. What Ransomnews independently established is that the published sample is consistent with a genuine export from McDonald’s Entra ID directory.

Is customer data affected?

Not in the sample. The 8,000 records reviewed contain only workforce data: names, work emails, job titles, employee IDs, work phone numbers and office or restaurant addresses. There are no customer records, no payment details and no passwords of any kind.

Is this the same as the McHire breach in 2025?

No. The 2025 incident involved Paradox.ai’s McHire recruitment chatbot and exposed data belonging to job applicants. This listing concerns the internal employee directory and comes from a different source entirely.

How old is the alleged McDonald’s data?

It cannot be dated precisely. The file contains no timestamps of any kind. The absence of Russian and Kazakh records, combined with the presence of Ukrainian ones, places the export somewhere in 2023 or later, which is a wide window rather than an answer.

Are 1.7 million records really for sale?

Unverified. The published sample is 8,000 records, which is 0.47% of the claimed total. The ratio of restaurant staff to corporate staff in the sample makes a figure of that order plausible for a company of McDonald’s size, but nothing in the sample proves the seller holds it.

Which other companies are named in the same campaign?

Eight others. The same account listed Hexaware Technologies, Kyndryl, Wyndham Hotels, InterContinental Hotels, HCL Technologies, Tata Consultancy Services, Vodafone and Gap Inc. between 1 and 16 August 2026. None of the nine organisations has confirmed anything.

How can an organisation stop this happening to its own directory?

Enforce phishing-resistant multi-factor authentication on every account including frontline staff, restrict default user permissions so ordinary accounts cannot enumerate the whole directory, and monitor for bulk Microsoft Graph read activity. Directory enumeration by a valid account generates almost no signal unless you are looking for it.

Sources and further reading

  • The Register, One criminal, 50 hacked organizations, and all because MFA wasn’t turned on
  • CSO Online, McDonald’s AI hiring tool’s password ‘123456’ exposed data of 64M applicants (unrelated 2025 incident, included for context)
  • Ransomnews, Initial access brokers and the ransomware supply chain

The Ransomnews Monthly

One email a month. Original leak-site data, victim census updates, and the findings that did not make the articles. No spam, unsubscribe any time.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous Article7.3M chess.com records leaked, and the data is real
Next Article Verified.ru: inside the archive of a cybercrime bureaucracy
Neringa Macijauskaitė
  • LinkedIn

Neringa Macijauskaitė is an information security researcher covering threat intelligence and cybercrime for Ransomnews. She has worked as an information security researcher, conducting threat intelligence investigations, tracking emerging cyber threats, and monitoring for exposed systems and online vulnerabilities. She is also part of the crew behind BSides Vilnius, the community-run security conference in Lithuania.

Related Posts

Verified.ru: inside the archive of a cybercrime bureaucracy

August 17, 2026

7.3M chess.com records leaked, and the data is real

August 12, 2026

Quake3 and morgot: tracing REvil’s source-code developer

August 10, 2026

Comments are closed.

// The Ransomnews Monthly

What leaked, what held up

One email a month: the datasets we verified, and the ones that fell apart under scrutiny.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

// Free tool

Were you in a leak?

Check whether an email address has surfaced in infostealer logs. No signup, no data stored.

Run StealerCheck

// Live data

Ransomtracker

Victims as they are posted to ransomware leak sites, tracked continuously and checked against the claims.

Open the tracker

9,459 confirmed attacks tracked

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.