[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Sign-in]  [Mail]  [Setup]  [Help] 

Status: Not Logged In; Sign In

To Prevent Strokes, Take Potassium.

Lawyer for Epstein VICTIMS Shares Details Trump FEARED THE MOST

WW3? French Hospitals Told To Prepare For A "Major Military Engagement" Within Six Months

The Zionist Experiment Is Over

Sen. Tim Kaine: ‘Extremely Troubling’ to Say Natural Rights Are from God

Israel & The Assassination Of The Kennedy Brothers

JEWISH RITUAL MURDER (Documentary)

The Pakistani mayor of Rotherham claims she proud to be British and proud to be Pakistani.

Khe Sanh 1968 How U.S. Marines Faced the Siege in Vietnam

Did Xi's Parade Flip The Script On US Defense Of Taiwan?

Cascade Volcanoes Show Weird Pulse Without Warning – Mount Rainier Showing Signs of Trouble!

Cash Jordan: Chicago Apartments RAIDED... ICE 'Forcibly Evicts' Illegal Squatters at 3AM

We are FINALLY turning the tide on 9/11 - The TRUTH is coming out | Redacted w Clayton Morris

Netanyahu SHAKEN as New Hostage Video DESTROYS IDF Lies!

We are FINALLY turning the tide on 9/11 VIDEO

Shocking Video Shows Ukrainian Refugee Fatally Stabbed On Charlotte Train By Career Criminal

Man Identifies as Cat to Cop

his video made her stop consuming sugar.

Shot And Bothered - Restored Classic Coyote & Road Runner Looney Tunes Cartoon 1966

How to Prove the Holocaust is a Hoax in Under 2 Minutes

..And The Legacy Media Wonders Why Nobody Trusts Them

"The Time For Real Change Is Now!" - Conor McGregor Urges Irish To Lobby Councillors For Presidential Bid

Daniela Cambone: Danger Not Seen in 40+ Years

Tucker Carlson: Whistleblower Exposes the Real Puppet Masters Controlling the State Department

Democrat nominee for NJ Governor, says that she will push an LGBTQ agenda in schools and WILL NOT allow parents to opt out.

Holy SH*T, America's blood supply is tainted with mRNA

Thomas Massie's America First : A Documentary by Tom Woods & Dan Smotz

Kenvue Craters On Report RFK Jr To Link Autism To Tylenol Use In Pregnancy

All 76 weapons at China 2025 military parade explained. 47 are brand new.

Chef: Strategy for Salting Steaks


World News
See other World News Articles

Title: McDonald's McHire AI Bot Just Exposed The Personal Data Of 64 McMillion People
Source: [None]
URL Source: https://www.zerohedge.com/markets/m ... sonal-data-64-mcmillion-people
Published: Jul 25, 2025
Author: Tyler Durden
Post Date: 2025-07-25 13:49:30 by Horse
Keywords: None
Views: 273
Comments: 1

A security lapse in McDonald’s job application system could have exposed the personal details of around 64 million people — all because someone used the password “123456", according to Tom's Hardware.

"That's amazing. We've got the same combination on our luggage!"

Researchers Ian Carroll and Sam Curry discovered serious flaws in McHire, the chatbot developed by Paradox.ai and used by most McDonald’s franchises for recruitment. While poking around, they found that internal accounts used by Paradox staff were protected by one of the most commonly guessed passwords in the world: “123456.”

The report says Carroll compared it to his own teenage mistake of using “1234” on a forum account. “That’s slightly better than the password I used, I guess,” he wrote, “but not enough to justify its use decades after most people realized that using weak passwords is a bad idea.”

Using that flimsy credential, the researchers gained administrative access — though initially only to a test restaurant account tied to Paradox employees. That let them explore the system, but didn’t prove any real-world risk. The real issue came when they found a second vulnerability: an insecure direct object reference (IDOR) flaw in the McHire API.

That bug let them pull sensitive data from any chat-based application submitted to McDonald’s — names, email addresses, phone numbers, home addresses, application details, and even login tokens that allowed full access to user chats and potentially more.

Paradox once boasted that 90% of McDonald’s franchises relied on McHire for hiring, though that claim has since quietly vanished from its blog.

To put things in context: Paradox raised $200 million in 2020. McDonald’s is worth over $200 billion. And yet a system handling tens of millions of people’s private information was essentially protected by the digital equivalent of a sticky note on a monitor.

The only silver lining? Carroll and Curry say the vulnerabilities were patched within 24 hours of being reported. With any luck, McDonald’s and Paradox will aim for better cybersecurity hygiene going forward — maybe even something a little more secure than “123456.”


Poster Comment:

France Will Recognize Palestinian State - US-Israeli Backlash Ensues

Netanyahu says recognition "rewards terror"-- but terror marked Israel's path to statehood too

https://www.zerohedge.com/geopolitical/france-will-recognize-palestinian-state-us- israeli-backlash-ensues

Post Comment   Private Reply   Ignore Thread  


TopPage UpFull ThreadPage DownBottom/Latest

#1. To: Horse (#0)

"Dumb" vulnerabilities may be intentional.

A rainbow coalition against Jews doesn't require Whites or Pro-Whites. It can be just as brown or anti-white as you like.

Prefrontal Vortex  posted on  2025-07-25   16:50:09 ET  Reply   Trace   Private Reply  


TopPage UpFull ThreadPage DownBottom/Latest


[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Sign-in]  [Mail]  [Setup]  [Help]