McDonald's, Vodafone, TCS, Kyndryl, and others named as researchers point to compromised credentials