Your Data on the Menu
A cascade of security failures at McDonald’s and its partners
The personal information of an estimated 64 million McDonald’s job applicants was exposed in a security incident that reached from the fast-food chain itself into the technology partners it hires. The blunders that made it possible were simple and preventable, which is precisely what makes the story unsettling.
The initial breach was shockingly simple. Security researchers found that McHire, the recruitment platform used by many McDonald’s franchisees and developed by AI hiring bot maker Paradox.ai, had an administration account with the username and password set to “123456”. That easily guessable password, combined with another vulnerability, let researchers access the personal data of millions of applicants, including names, email addresses, and phone numbers.
Paradox.ai initially described the incident as isolated and involving a test account. Further digging uncovered a wider pattern of poor security practices. A report from Krebs on Security found that a Paradox.ai developer’s computer was infected with malware that stole hundreds of passwords, including credentials for other Fortune 500 clients of Paradox.ai and the developer’s login for the company’s single sign-on platform, with a cookie valid for months.
The problems did not stop at Paradox.ai. Another researcher cataloged a long list of vulnerabilities inside McDonald’s own systems: a marketing hub “protected” by a client-side password, passwords emailed in plaintext, exposed API keys, and a system that let any crew member look up any employee in the company, from store managers to the CEO. The same researcher found an internal tool for franchise owners with no authentication at all for administrative functions.
Reporting the problems proved almost as hard as finding them. One researcher had to cold-call McDonald’s corporate headquarters and guess employee names after the company’s security contact information was removed from its website. A McDonald’s employee who helped identify some of the flaws was reportedly fired for “security concerns from corporate”.
A company’s security is only as strong as its weakest link, and that link often sits in the supply chain or in internal habits nobody filed under ‘security’. For job applicants, the takeaway is that the data handed to one recruiter can end up on a system protected by a password like “123456”. For companies, the fix is unglamorous: real internal controls and reporting channels that do not get the messenger fired. Reporters who dig up holes like these should not have to find the security team by cold-calling the front desk.