McDonald's AI hiring chatbot left open by '123456' default credentials
Jun 2025
Researchers accessed McHire's admin with default '123456' credentials and an IDOR, exposing up to 64 million applicant records before Paradox.ai patched the issues after disclosure.
Incident Details
Perpetrator:Vendor/Developer
Severity:Facepalm
Blast Radius:Up to 64M applicant records exposed; vendor patched; reputational risk.
Tech Stack
AI chatbotHiring platformAuthenticationIDOR
References
Wired: McDonald's AI Hiring Bot Exposed Millions of Applicants' Data to Hackers Who Tried the Password '123456' ↗Ian Carroll: Would you like an IDOR with that? Leaking 64 million McDonald's job applications ↗CSO Online: McDonald's AI hiring tool's password '123456' exposed data of 64M applicants ↗