logo

McDonald’s Employee Data Appears in Leak, Seller Claims 1.7M Records Stolen

ID: 7ee420f2-4959-5e31-872c-906a6715b99b

STIX ID: report--7ee420f2-4959-5e31-872c-906a6715b99b

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2026-08-17

Date Updated: 2026-08-19

Author: Pierluigi Paganini

...
...

A seller posted an 8,000-row sample claimed to be part of a 1.7M-record dump of McDonald’s employee directory allegedly taken from its Azure/Entra ID tenant using compromised credentials; forensic indicators in the file (column names, encoding errors, internal domains and addresses) make the export appear authentic, but the sample cannot confirm the dump’s age or full size. The pattern of similar listings suggests infostealer-harvested credentials being reused across tenants; the exposed data contains personal and role information that enables targeted social-engineering attacks even though no passwords or hashes were present.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.