Back to Exposure Report
Cross-Sector / Identity DataAugust 2026Global

McDonald’s — TheHatman campaign

Nine unrelated global enterprises. Same actor, same window, same field list. That last part is the finding.

Full namesEmail addressesJob titlesPhone numbersPostal addressesEmployee IDsService accounts
1

What happened?

An actor operating as TheHatman claimed a series of breaches across unrelated global enterprises during August 2026. Reported volumes include roughly 1.7 million records at McDonald's, 800,000 at TCS, 425,000 at Vodafone, 250,000 at HCL Technologies, 185,000 at InterContinental Hotels, 170,000 at Kyndryl, 80,000 at Gap, 20,000 at Hexaware, and 9,000 at Wyndham Hotels.

Separate reporting in the same period describes approximately 3.64 million records tied to Fortune 500 employee data in Microsoft Azure environments. The claims have not been independently verified and the named companies have not, in most cases, publicly confirmed.

2

What data was actually inside?

Reported fields across the affected organizations: full names, email addresses, job titles, phone numbers, postal addresses, employee IDs, and service and tenant accounts.

Look at the fields rather than the brand names. Job titles and employee IDs are not customer attributes. This is corporate directory data — the internal record of who works somewhere, what they do, and how to reach them.

Nine unrelated companies producing the same field list points toward a shared platform or common exposure rather than nine independent intrusions.

3

Who gets hurt and how?

Employees, and then their employers. Nobody's identity gets stolen from a job title, which is exactly why this data is under-defended.

A complete directory with names, titles, reporting context, and direct phone numbers is the input for every social engineering campaign that follows. It tells an attacker who the help desk staff are, who has administrative titles, who is senior enough to be obeyed and junior enough to comply, and how to reach them directly. Voice phishing against help desks has been the dominant enterprise entry vector through 2026, and it runs on precisely this material.

Service and tenant accounts are worse. Those are not people; they are non-human identities that frequently hold broad permissions, rarely rotate credentials, and almost never have multi-factor authentication.

4

What did they think they were doing right?

Every organisation named runs a substantial security programme, and several are IT services firms that sell security to others. Their customer data is classified, encrypted, access-controlled, and audited, because that is what regulation and customer contracts demand.

Directory data receives none of that treatment, and the reasoning is superficially sound: it is not regulated personal data in most jurisdictions, it is deliberately visible internally so people can find each other, and much of it appears on business cards and public profiles anyway. The gap between a scattered public presence and a complete structured export of the whole organisation is the part that assumption misses.

5

What did they not know about their own data?

Almost every enterprise can produce a data map of its customer records. Very few have ever inventoried where employee directory data has been replicated — and it is replicated everywhere, because every internal system needs to know who people are.

The identity provider holds it. So does the HR system, the ticketing platform, the collaboration suite, the badge system, the expense tool, the CRM's internal user table, and every integration built between them. Each copy was created for a legitimate reason and none is on a classification list, because directory data is treated as infrastructure rather than as data.

That is how nine unrelated companies end up exposed through the same field list at the same time. The common factor is not a shared vendor relationship anyone documented. It is a category of data nobody was watching.

If you use cloud storage, do you know what sensitive data lives in your buckets and blobs? Or would you find out the same way they did?

6

What does attribution look like the morning after?

Employee data is personal data under GDPR, so European employees at Vodafone, InterContinental, and the IT services firms engage the 72-hour supervisory authority clock. US state statutes are more equivocal — a name and job title frequently falls below the notification threshold, which means the most operationally dangerous exposure may generate the least regulatory obligation.

The urgent work is not notification. It is defensive: every affected organisation should assume its help desk will receive convincing calls referencing real employees, real titles, and real phone numbers, and should harden identity verification procedures immediately. That is a security response rather than a compliance one, and no statute requires it.

7

What would have changed the outcome?

Treating the employee directory as a classified dataset, and knowing every system holding a copy of it.

Your customer database is inventoried because a regulator made you. Your employee directory is replicated across a dozen systems, exported to spreadsheets, synced into SaaS tools, and appears on no data map — while being the single most useful dataset for the attack technique that is currently working best against enterprises. The exposure that leads to your next incident is not always the one with a notification obligation attached. See also our analysis of the Brinks Home breach, where a vishing call opened the door.

The organizations TheHatman listed found out the hard way.

Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.