See every side of every news story
Published loading...Updated

McDonald’s AI Hiring Bot Exposed Millions of Applicants’ Data to Hackers Who Tried the Password ‘123456’

UNITED STATES, JUL 11 – Security flaws in McDonald's AI hiring platform exposed data of 64 million applicants due to a weak password and API flaw, with fixes applied within a day, researchers said.

  • On June 30, cybersecurity experts Ian Carroll and Sam Curry identified a security flaw in McDonald's AI-driven hiring system, McHire, which resulted in the exposure of personal information belonging to 64 million job seekers across the United States.
  • The flaw stemmed from weak default admin credentials of '123456' used in McHire’s chatbot backend and an IDOR bug that allowed unauthorized data access.
  • Researchers were able to access extensive conversation records, authentication tokens, and sensitive applicant information collected by Olivia, the AI chatbot responsible for screening 90 percent of job candidates at McDonald's franchises.
  • Paradox.ai and McDonald's confirmed the issue, promptly disabled default credentials, deployed a fix the same day, and initiated a system review with plans for a bug bounty program.
  • The breach highlights risks in AI hiring systems using weak security, prompting McDonald's and Paradox.ai to strengthen protections and enforce third-party accountability.
Insights by Ground AI
Does this summary seem wrong?

89 Articles

Lean Left

Some Americans who applied for McDonald's have their data at risk because the recruitment system had "123456"... as a password.

·Montreal, Canada
Read Full Article
Lean Right

Last June, two cybersecurity researchers discovered that McDonald's chatbot recruitment platform, called Olivia/mChire, was protected by extremely weak standard credentials. Platform used by...

·Portugal
Read Full Article
Lean Right

Two researchers managed to access personal data from people who applied for jobs at McDonald's . How? By using the password "123456," reports Wired. - So, I started applying for a job and after 30 minutes I had full access to pretty much every application made to McDonald's for several years, security researcher Ian Carrol told the magazine.

·Stockholm, Sweden
Read Full Article
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 59% of the sources lean Left
59% Left
Factuality

To view factuality data please Upgrade to Premium

Ownership

To view ownership data please Upgrade to Vantage

IT PRO broke the news in on Wednesday, July 9, 2025.
Sources are mostly out of (0)

You have read 1 out of your 5 free daily articles.

Join millions of well-informed readers who use Ground to compare coverage, check their news blindspots, and challenge their worldview.