Morning Overview

A hacker is selling stolen employee data from McDonald’s, Gap and other giants

A cybercriminal has been advertising huge caches of stolen corporate data, claiming to hold employee records lifted from some of the world’s largest companies, including McDonald’s and Gap. The seller has listed the data on an online forum, offering names, contact details, and internal identifiers that could expose thousands of workers to fraud and identity theft.

The listings are part of a broader campaign that names a roster of household brands, and they highlight a growing weakness in how big organizations secure their cloud accounts. While some of the claims are disputed, the incident underscores how a single set of stolen login credentials can put an entire company’s workforce at risk.

According to a security roundup published by Privacy Guides, a threat actor operating under an alias began advertising the data dumps at the end of July 2026. The seller claimed to have roughly 3.64 million records in total, spanning multiple corporations, with the data allegedly pulled from the companies’ cloud environments.

The McDonald’s employee records

The most detailed claim involves McDonald’s. The seller advertised an alleged 1.7 million employee records taken from the company, describing an internal dump of staff information. The fields on offer reportedly included names, employee identification numbers, email addresses, job titles, phone numbers, and postal addresses, along with internal service accounts and other tenant records.

Data of that kind is valuable precisely because it is specific and verifiable. With names tied to job titles, corporate emails, and phone numbers, criminals can craft convincing phishing messages aimed at particular employees or impersonate staff to trick colleagues and vendors. The combination of personal and workplace details makes such a leak far more dangerous than a list of random email addresses.

How the data was allegedly taken

The seller said the information was downloaded directly from Microsoft Azure cloud tenants using compromised credentials. In other words, rather than breaking through firewalls, the attacker appears to have simply logged in with valid usernames and passwords that had fallen into the wrong hands, then exported the data the accounts could reach.

Security researchers traced a likely origin for those stolen logins. As reported by BleepingComputer, analysts linked the compromised credentials to infostealer malware, a type of program that silently harvests saved passwords and session tokens from infected computers. Those harvested credentials can then be sold or reused to access corporate systems, turning one infected device into a doorway to a company’s cloud.

Gap disputes the breach

Not every company on the list accepts the seller’s account. Gap was named with about 80,000 records offered for sale, but the retailer said it found no evidence of a breach of its systems. The company suggested that the attacker had repackaged data from an older, unrelated incident and presented it as a fresh theft.

That kind of dispute is common in the murky world of data-leak forums, where sellers have an incentive to inflate the scale and freshness of their wares. Old data recycled and rebranded as new can still cause harm if the information remains valid, but it also means the headline totals advertised by criminals should be treated with caution until independently verified.

The other companies named

McDonald’s and Gap were only part of the campaign. The same seller listed data attributed to a spread of major firms, including the telecommunications company Vodafone, the IT services giants Tata Consultancy Services and HCL Technologies, the hotel operator InterContinental Hotels Group, and the technology services company Kyndryl. The common thread was cloud accounts accessed with stolen credentials.

The pattern points to a systemic problem rather than a single unlucky victim. When many large organizations rely on the same cloud platforms and their employees’ machines are exposed to credential-stealing malware, one technique can be pointed at target after target. That repeatability is what allowed a single actor to assemble dumps from so many well-known names at once.

What the campaign reveals about cloud security

The episode is a reminder that stolen passwords, not exotic hacking, drive many modern breaches. Defenses such as multi-factor authentication, tighter monitoring of unusual logins, and prompt cleanup of malware-infected devices can blunt this exact style of attack, yet the recurring appearance of Azure-based thefts shows those safeguards are unevenly applied.

For the employees whose information ends up on a forum, the practical fallout is heightened risk of targeted phishing and identity fraud, often long after the initial theft. The broader lesson for organizations is that protecting a workforce increasingly means protecting the credentials that unlock the cloud, because once those keys leak, the data behind them can be quietly copied and sold.

Individuals caught up in a leak like this have limited but real options, from watching for unexpected password-reset messages to treating any urgent-sounding email that references a job title or employer with suspicion. Companies, for their part, face pressure to detect malware-infected devices faster and to assume that any credential exposed to the open internet may already be compromised. The campaign is likely to keep surfacing new names as researchers verify which listings are genuine and which are recycled from older thefts dressed up as fresh hauls.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview