// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-newsDTG 0600Z
ColdRecon / Breach Radar / McDonald's, Vodafone
Breach Record

McDonald's, Vodafone

DISCLOSED 2026-08-19 · STOLEN CREDS

A threat actor is selling internal employee directories stolen from McDonald's and Vodafone via an Azure credential theft campaign. The data is being offered on the dark web. The breach involves unauthorized access to Azure environments using stolen credentials.

The record

What we know

Disclosed
2026-08-19
Attack vector
Stolen Creds
Sector
Food & Beverage, Telecommunications
Data classes exposed
employee directories
ColdRecon assessment

Could a positive-security control have prevented this?

Verdict · unclear · opinion

Insufficient information to assess whether a positive-security model would have prevented this attack, as the specific method of credential theft and subsequent exfiltration is not detailed.

Our assessments are opinion, grounded in the cited public facts. Read them critically.

Sources

Cited reporting

Similar vector · recent

Other stolen creds breaches on file

This page is the permanent ColdRecon entry for the McDonald's, Vodafone disclosure. It updates if new public reporting emerges. All tracked breaches →

McDonald's, Vodafone just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →