McDonaldâs Employee Data Appears in Leak, Seller Claims 1.7M Records Stolen
A seller on a data-trading forum posted an 8,000-row sample this week claiming it came from McDonaldâs own Azure tenant, part of a supposed 1.7 million-record employee directory obtained using stolen credentials. Ransomnewsâs technical breakdown found the sample holds up as genuine on every test that can be run against it. What it canât confirm, notably, is exactly how old the data is or whether the full 1.7 million figure is real.
âThe listing is a straightforward private sale, posted at 4:08 AM forum time under the title âMcDonalds 1.7M+ Azure Internal Employee Dumpâ. The seller, an account called TheHatman, writes that the data was âdownloaded directly from Azure Tenant using compromised credentialsâ and that it contains âemployee accounts, service accounts, and other tenant account recordsâ. No price is named. Buyers are invited to make offers.â reads the report published by Ransomnews.
âTo evidence the claim, the seller attached a free 8,000-record sample. That file is the entire basis for what follows. Ransomnews analysed it offline. We did not access, probe or authenticate against any McDonaldâs system, and we have redacted the sampleâs download location from the screenshot below because it still resolves to real peopleâs contact details.â
The fileâs structure gives away exactly what it is before you even read a single row. Column names like FacsimileTelephoneNumber and PhysicalDeliveryOfficeName arenât something anyone invents; theyâre the exact property names Microsoftâs own PowerShell directory tools return when an administrator exports a user list from Entra ID, the modern name for Azure Active Directory. Whoever produced this file ran a standard Microsoft export command and saved the output, nothing more exotic than that.
Every one of the 50 email domains found in the sample is genuinely McDonaldâs-controlled, spanning corporate staff, restaurant crew accounts, franchisee logins, and vendor guest access across more than thirty countries. Three rows even carry the tenantâs own built-in Microsoft address, mcdonaldscorp.onmicrosoft.com
, something thatâs invisible from outside the organization and simply isnât guessable or scrapeable.
Add in 233 rows with the exact kind of garbled text encoding that happens when someone forgets to specify UTF-8 during an export, plus 85 job titles cut off at precisely 30 characters mid-word, the unmistakable fingerprint of a fixed-width HR system field bleeding into the directory, and you get a picture consistent with a real export rather than something assembled from public sources.
âThe file is broken in the ways real exports are broken. 233 rows contain mangled characters: Königswinter appears as âKönigswinterâ, MĂŒnchen as âMĂÂŒnchenâ, and Ukrainian job titles are rendered as unreadable strings of Cyrillic run through the wrong character set. This is what happens when somebody runs Export-Csv
without specifying UTF-8 encoding.â continues the report. âItâs a mistake, and it is not the kind of mistake anybody makes on purpose. A fabricated dataset doesnât come with authentic encoding damage.â
One detail actually reaches outside the file entirely. A restaurant entry for â556 Uptonâ on Upton By-Pass in Wirral, complete with phone number, matches a real, publicly listed McDonaldâs location down to the digit. Thatâs a small anchor, but itâs the kind of anchor fabricated data doesnât usually survive contact with.
What the sample genuinely canât settle is timing. There isnât a single date field anywhere in the schema, no creation date, no last login, nothing to age a row by. âWe can say with confidence that the data came out of McDonaldâs directory. We cannot say from the file alone when it came out.â The best clue available is McDonaldâs own market footprint: no Russian records at all, consistent with the companyâs 2022 exit, and no Kazakh ones either, which points to sometime in 2023 or later, a wide window rather than a firm date.
The 1.7 million headline number also isnât something 8,000 rows can verify. That sample is under half a percent of the claim, and while nothing in it looks implausible given McDonaldâs global workforce size, plausible isnât the same thing as confirmed. A seller running a volume trade across multiple companies has every incentive to round the number up in the listing title.
This McDonaldâs post wasnât an isolated event either. The same account, going by TheHatman, posted nine listings in total over sixteen days, claiming roughly 3.6 million records combined across McDonaldâs, Vodafone, Gap, two hotel chains, and four major IT outsourcing firms including Kyndryl and Tata Consultancy Services.
Every listing uses an identical 19-column schema and nearly identical wording, the kind of consistency you get from one person running the same export script against whatever tenant they currently hold a working login for, not from someone fabricating nine separate datasets by hand.
That pattern points toward something fairly mundane and fairly common: infostealer malware harvesting saved credentials at scale, feeding a resale market that lets one operator walk into tenant after tenant using logins nobody bothered to protect with multi-factor authentication. Reading an entire company directory doesnât require a sophisticated intrusion; it requires one working account in a tenant that hasnât restricted user enumeration, which is Entra IDâs default setting unless an administrator has explicitly locked it down.
For anyone at McDonaldâs or one of the other eight listed companies, the real risk here isnât account takeover, since there are no passwords or hashes in the sample at all. Itâs social engineering: full names, job titles, direct phone numbers, and internal email formats are more than enough to make a fake helpdesk call or a fraudulent invoice sound completely legitimate. Treat unsolicited contact that already knows your role and your location with more suspicion than usual, because thatâs precisely the kind of detail this file was built to hand someone.
âFor individuals named in the data, there is no action that removes the exposure.â concludes the report.âThe realistic response is scepticism about unsolicited contact that arrives already knowing your role and your store, and a refusal to act on instructions that arrive by phone or email without out-of-band confirmation.â
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs â hacking, McDonaldâs)
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content â general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached â you'll always get the same 5 for this article.