[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Sign-in]  [Mail]  [Setup]  [Help] 

Status: Not Logged In; Sign In

Opioids More Likely To Kill Than Car Crashes Or Suicide

The association between COVID-19 “vaccines” and cognitive decline

Democrats Sink to Near Zero in New Gallup Poll, Theyre Just Not Satisfied

She Couldn't Read Her Own Diploma: Why Public Schools Pass Students but Fail Society

Peter Schiff: Gold To $6,000 Next Year, Dollar Index To 70

Russia Just Admitted Exactly What Everyone – But Trump – Already Knew About Putin's Ukraine Plans

Sex Offenses in London by Nationality

Greater Israel Collapses: Iran the Next Target

Before Jeffrey Epstein: The FINDERS

Cyprus: The Israeli Flood Has Become A Deluge

Israel Actually Slaughtered Their Own People On Oct 7th Says Israeli Newspaper w/ Max Blumenthal

UK Council Offers Emotional Support To Staff "Discomforted" By Seeing The National Flag

Inside the Underground City Where 700 Trucks Come and Go Every Day

Fentanyl Involved In 70% Of US Drug Overdose Deaths

Iran's New Missiles. Short Version

Obama Can't Bear This. Kash Patel Exposes Dead Chef Revelation. Obama’s Legacy DESTROYED!

Triple-Digit Silver Imminent? Critical Mineral, Backwardation & Remonetization | Mike Maloney

Israel Sees Sykes-Picot Borders As 'Meaningless' & 'Will Go Where They Want': Trump Envoy

Bring Back Asylums: It's Time To Talk About Transgender Fatigue In America

German Political Parties (Ex-AfD) Sign 'Fairness Pact' That Prevents Criticizing Immigration

CARVING .45 CALIBER AUTOMATICS OUT OF STEEL WWII UNION SWITCH AND SIGNAL MOVIE

This surprising diabetes link could protect your brain

Putin and Xi to lay foundations for a new world order in Beijing

Cancer Natural Solutions Q&R

Is ANYONE buying this anymore? (Netanyahu)

Mt Etna in Sicily Eupting

These Soviet 4x4 Sedans Are Cooler Than You Think!

SSRIs and School Shootings, FDA Corruption, and Why Everyone on Anti-Depressants Is Totally Unhappy

St. Louis Man Who Gunned Down Police Officer Demond Taylor Is Released on $5,000 Bond

How Israeli spy veterans are shaping US big tech


World News
See other World News Articles

Title: McDonald's McHire AI Bot Just Exposed The Personal Data Of 64 McMillion People
Source: [None]
URL Source: https://www.zerohedge.com/markets/m ... sonal-data-64-mcmillion-people
Published: Jul 25, 2025
Author: Tyler Durden
Post Date: 2025-07-25 13:49:30 by Horse
Keywords: None
Views: 203
Comments: 1

A security lapse in McDonald’s job application system could have exposed the personal details of around 64 million people — all because someone used the password “123456", according to Tom's Hardware.

"That's amazing. We've got the same combination on our luggage!"

Researchers Ian Carroll and Sam Curry discovered serious flaws in McHire, the chatbot developed by Paradox.ai and used by most McDonald’s franchises for recruitment. While poking around, they found that internal accounts used by Paradox staff were protected by one of the most commonly guessed passwords in the world: “123456.”

The report says Carroll compared it to his own teenage mistake of using “1234” on a forum account. “That’s slightly better than the password I used, I guess,” he wrote, “but not enough to justify its use decades after most people realized that using weak passwords is a bad idea.”

Using that flimsy credential, the researchers gained administrative access — though initially only to a test restaurant account tied to Paradox employees. That let them explore the system, but didn’t prove any real-world risk. The real issue came when they found a second vulnerability: an insecure direct object reference (IDOR) flaw in the McHire API.

That bug let them pull sensitive data from any chat-based application submitted to McDonald’s — names, email addresses, phone numbers, home addresses, application details, and even login tokens that allowed full access to user chats and potentially more.

Paradox once boasted that 90% of McDonald’s franchises relied on McHire for hiring, though that claim has since quietly vanished from its blog.

To put things in context: Paradox raised $200 million in 2020. McDonald’s is worth over $200 billion. And yet a system handling tens of millions of people’s private information was essentially protected by the digital equivalent of a sticky note on a monitor.

The only silver lining? Carroll and Curry say the vulnerabilities were patched within 24 hours of being reported. With any luck, McDonald’s and Paradox will aim for better cybersecurity hygiene going forward — maybe even something a little more secure than “123456.”


Poster Comment:

France Will Recognize Palestinian State - US-Israeli Backlash Ensues

Netanyahu says recognition "rewards terror"-- but terror marked Israel's path to statehood too

https://www.zerohedge.com/geopolitical/france-will-recognize-palestinian-state-us- israeli-backlash-ensues

Post Comment   Private Reply   Ignore Thread  


TopPage UpFull ThreadPage DownBottom/Latest

#1. To: Horse (#0)

"Dumb" vulnerabilities may be intentional.

A rainbow coalition against Jews doesn't require Whites or Pro-Whites. It can be just as brown or anti-white as you like.

Prefrontal Vortex  posted on  2025-07-25   16:50:09 ET  Reply   Trace   Private Reply  


TopPage UpFull ThreadPage DownBottom/Latest


[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Sign-in]  [Mail]  [Setup]  [Help]