// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-newsDTG 0600Z
ColdRecon / Breach Radar / McDonald's, Vodafone, Kyndryl & Others
Breach Record

McDonald's, Vodafone, Kyndryl & Others

DISCLOSED 2026-08-22 · STOLEN CREDS

A threat actor known as 'TheHatman' has posted internal employee directories from several Fortune 500 companies, claiming they were extracted from the organizations' Azure tenants. The data was obtained using compromised credentials. The affected companies include McDonald's, Vodafone, and Kyndryl.

The record

What we know

Disclosed
2026-08-22
Attack vector
Stolen Creds
Data classes exposed
employee directories
Sources

Cited reporting

Similar vector · recent

Other stolen creds breaches on file

This page is the permanent ColdRecon entry for the McDonald's, Vodafone, Kyndryl & Others disclosure. It updates if new public reporting emerges. All tracked breaches →

McDonald's, Vodafone, Kyndryl & Others just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →