[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Sign-in]  [Mail]  [Setup]  [Help] 

Status: Not Logged In; Sign In

Trump biographer says White Houseinsider texted blunt, profane message after Alaska summitt

Karmelo Anthony’s Parents KICKED OUT From Mansion After $30M in Debt

European Countries That Will COLLAPSE (Due To Immigration)

Netanyahu Gov't CRASHES as IDF Soldiers Turn on Each Other in Tel Aviv!

Two Tier UK: 'Cut Throats' Councilor Freed, While Mother Who Tweeted Still In Prison

Closest Thing We Have to a Fountain of Youth

The ultimate American inner city showdown

Israel Is So Evil That It Has A Military Unit Dedicated To Excusing Atrocities

42 Million Chinese Forced to Cut Social Security, Youth Begin Full Rebellion Against Old Leaders

Walmart Leaves Chicago, Closes 4 Stores After Community Steals Them Blind, Losing Millions

ICE Agents RAID California Costco Warehouse — 900+ Illegals Captured in Minutes!

Mexicans WANT Trump to invade to stop the cartels

Lee Rodgers and Melanie Morgan Interview a "Turkey Tugger"

Sounding the Alarm On Transformer Shortage Amid AI Data Center Boom

Peter Zeihan: China’s Fall, America’s Rise, and the End of the World Order

6 Year Old Black Girl Helps Solve A Double Homicide

Associated Press Tried to Fact-Check Trump on DC Crime and Accidentally Proved He Was Right All Along

The Sinking of IJN Musashi — How Airpower Crushed the World’s Largest Battleship

Young Woman’s Mockery of the Left’s ‘No Kings’ Hypocrisy Racks Up Millions of Views

Israel Alarmed Over Suspected Chinese Support For Iranian Missile Program

Seth Harp Exposes the Murder & Drug Trafficking Taking Place Inside America’s Largest Military Base

Holy SH*T Their planning WHAT in Gaza???!!! This explains EVERYTHING

Crowds on Demand CEO provides insight as paid protester requests up 400% under Trump

Cash Jordan: Looters 'Wipe Out' 37 DC Stores... Mayor FLEES as Trump SEIZES Capital

MAHA Advocates Urge Trump To Block Immunity For Pesticide And Chemical Manufacturers

EVERYTHING IS STUPID!! - (Republican Town Hall edition)

Obama Called: Mamdani is Democrats' Future!

ICE Agents SHUTS DOWN Denver Hotel — Illegals Removed from Staff and Guests!

Cash Jordan: Homeless HORDE 'Digs In'... as Trump's 'Removal Unit' LEVELS DC Vagrant Village

AI-Powered Radar Can Now Spy On Your Phone Calls From 10 Feet Away


World News
See other World News Articles

Title: McDonald's McHire AI Bot Just Exposed The Personal Data Of 64 McMillion People
Source: [None]
URL Source: https://www.zerohedge.com/markets/m ... sonal-data-64-mcmillion-people
Published: Jul 25, 2025
Author: Tyler Durden
Post Date: 2025-07-25 13:49:30 by Horse
Keywords: None
Views: 123
Comments: 1

A security lapse in McDonald’s job application system could have exposed the personal details of around 64 million people — all because someone used the password “123456", according to Tom's Hardware.

"That's amazing. We've got the same combination on our luggage!"

Researchers Ian Carroll and Sam Curry discovered serious flaws in McHire, the chatbot developed by Paradox.ai and used by most McDonald’s franchises for recruitment. While poking around, they found that internal accounts used by Paradox staff were protected by one of the most commonly guessed passwords in the world: “123456.”

The report says Carroll compared it to his own teenage mistake of using “1234” on a forum account. “That’s slightly better than the password I used, I guess,” he wrote, “but not enough to justify its use decades after most people realized that using weak passwords is a bad idea.”

Using that flimsy credential, the researchers gained administrative access — though initially only to a test restaurant account tied to Paradox employees. That let them explore the system, but didn’t prove any real-world risk. The real issue came when they found a second vulnerability: an insecure direct object reference (IDOR) flaw in the McHire API.

That bug let them pull sensitive data from any chat-based application submitted to McDonald’s — names, email addresses, phone numbers, home addresses, application details, and even login tokens that allowed full access to user chats and potentially more.

Paradox once boasted that 90% of McDonald’s franchises relied on McHire for hiring, though that claim has since quietly vanished from its blog.

To put things in context: Paradox raised $200 million in 2020. McDonald’s is worth over $200 billion. And yet a system handling tens of millions of people’s private information was essentially protected by the digital equivalent of a sticky note on a monitor.

The only silver lining? Carroll and Curry say the vulnerabilities were patched within 24 hours of being reported. With any luck, McDonald’s and Paradox will aim for better cybersecurity hygiene going forward — maybe even something a little more secure than “123456.”


Poster Comment:

France Will Recognize Palestinian State - US-Israeli Backlash Ensues

Netanyahu says recognition "rewards terror"-- but terror marked Israel's path to statehood too

https://www.zerohedge.com/geopolitical/france-will-recognize-palestinian-state-us- israeli-backlash-ensues

Post Comment   Private Reply   Ignore Thread  


TopPage UpFull ThreadPage DownBottom/Latest

#1. To: Horse (#0)

"Dumb" vulnerabilities may be intentional.

A rainbow coalition against Jews doesn't require Whites or Pro-Whites. It can be just as brown or anti-white as you like.

Prefrontal Vortex  posted on  2025-07-25   16:50:09 ET  Reply   Trace   Private Reply  


TopPage UpFull ThreadPage DownBottom/Latest


[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Sign-in]  [Mail]  [Setup]  [Help]