GoFirm
Back to Blog
Case Studies·4 min read

McDonald's, Vodafone and seven other Fortune 500 companies had MFA enabled. None of it stopped a stolen session cookie.

By GoFirm

On 17 August 2026, a threat actor operating under the alias TheHatman began flooding underground cybercrime forums with datasets it claimed had been extracted from the Microsoft Azure and Entra cloud environments of nine major organisations. McDonald's Corporation topped the list at an alleged 1.7 million records, followed by Tata Consultancy Services (TCS) at roughly 800,000, Vodafone Group at approximately 425,000, and HCL Technologies, InterContinental Hotels Group (IHG), Kyndryl, Gap Inc., Hexaware Technologies and Wyndham Hotels making up the remainder. TheHatman claims the access came from password spraying combined with multi-factor authentication fatigue, the technique of bombarding an employee with repeated push approval requests until one gets tapped through out of irritation or exhaustion, rather than a single stolen password.

The security firm Hudson Rock says the pattern of victims points to something more targeted than a platform-wide flaw: infostealer malware, not a zero-day in Azure, appears to have harvested the credentials and session tokens that opened each tenant. Once inside, the attacker did not need to move laterally through a network or crack anything further. Azure and Entra directory services handed over employee names, job titles, phone numbers, department structures, manager relationships, service account details and, in several listings, Global Administrator account records, all through interfaces designed to let an already-authenticated session simply ask for the organisation chart.

The affected companies have pushed back on the scale of the claims. TCS told the Bombay Stock Exchange on 10 August that it found no credible evidence of a breach of its own systems, and that the referenced data appeared to be more than four years old and limited to basic employee information. Vodafone said its assessment points to old employee information, the kind that would appear on a business card, with no customer data or impact identified. TheHatman has not withdrawn the listings, and the samples shared to date, according to Hudson Rock, are structurally consistent with genuine Azure directory exports.

Whatever the true age of the data, the campaign illustrates a pattern now playing out across enterprise cloud environments industry-wide: stolen credentials and session cookies, harvested quietly by infostealer malware sitting on an employee's device, are proving sufficient to walk out with an organisation's entire internal directory. Security researchers on industry forums have pointed out that the affected companies are not small, poorly resourced targets. They are Fortune 500 enterprises with dedicated security teams and, by any conventional standard, mature multi-factor authentication programmes. None of it stopped the export.

The defences that failed here were not weak by conventional standards. Multi-factor authentication was in place at every named organisation. What MFA does not do, however well implemented, is verify that the human being tapping "approve" actually intended to approve that specific request, at that specific moment, for that specific action. MFA fatigue attacks exploit exactly that gap: repeated push prompts sent until a tired or distracted employee taps through one without reading it. A stolen session cookie exploits the same weakness from a different angle, replaying an already-approved session so no further approval is even asked for. Neither scenario involves a named, accountable human confirming that a directory export, a privilege escalation, or an administrative login was something they actually authorised.

A bulk export of an Entra directory, particularly one touching Global Administrator account records, is an execution event. Before that export can run, before a privileged session can be created from a new device or location, a confirmation request goes to the named authority accountable for that system, delivered to their registered device over a separate channel from the one the session itself is running on. The authority must provide a live biometric confirmation, a fingerprint or face match on hardware the attacker does not control, before the export or the escalation is permitted to proceed. No amount of push-notification fatigue changes that requirement, because there is no repeatable prompt to exhaust: a single, deliberate, out-of-band confirmation either happens or the action is blocked.

This closes both routes TheHatman is reported to have used. Password spraying that succeeds still cannot produce a login without triggering the confirmation, because the privileged action that follows the login is the event under control, not the password. A stolen session cookie, replayed from an infostealer log months after the original approval, cannot produce a fresh biometric confirmation from the actual named authority on their actual registered device. A stolen credential, however current or however old, cannot pass for a living person's fingerprint on a device it does not possess. The execution boundary holds regardless of how the access was obtained.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence and governance network for Security, Resilience & Defence teams.

References


1. Okunytė, P. 2026. Hackers are dumping millions of records from McDonald's, Vodafone, and other Fortune 500 companies. Cybernews, 17 August 2026 (updated 19 August 2026).
2. Hudson Rock. 2026. Massive Azure exfiltration campaign exposes millions of enterprise records via compromised credentials: McDonald's, Vodafone, Kyndryl and others. Infostealers.com, August 2026.
3. Tata Consultancy Services. 2026. Clarification on media reports regarding data security. Bombay Stock Exchange corporate filing, 10 August 2026.

Share this article