Skip to main content
Breach Signal

Breach report

Food & Restaurants

McDonald's (Paradox.ai McHire)

'123456' password exposed chats for 64 million McDonald's job chatbot applications

Security researchers found that McDonald's AI hiring platform, built by Paradox.ai, could be accessed with the password '123456', exposing records from up to 64 million job applications before the flaw was fixed in June 2025.

Reported by BleepingComputer

Records exposed

64M

Up to 64 million job application records

Scale vs. largest on file

When
2025
How they got in
Default admin credentials ('123456') and insecure direct object reference (IDOR) in hiring platform API
Sector
Food & Restaurants

In late June 2025, security researchers Ian Carroll and Sam Curry began examining McHire, the recruiting website used by the vast majority of McDonald's franchisees in the United States. The platform, built by Arizona-based Paradox.ai, uses an AI chatbot called Olivia to screen applicants, collect contact details and schedule interviews. The researchers discovered that an administrative login for a test restaurant account accepted the username and password 123456, with no multifactor authentication.

Once logged in, they found a second flaw: an insecure direct object reference in an internal API. By changing a sequential identifier in web requests, anyone with access could retrieve other applicants' records. The researchers estimated that the system held about 64 million application records, including names, email addresses, phone numbers and home addresses, as well as full chatbot transcripts, shift availability, personality test responses and authentication tokens that could be used to impersonate applicants.

Carroll and Curry reported the issues on June 30, 2025. Paradox.ai and McDonald's said the test account was disabled and the API flaw fixed the same day. Paradox said the test credentials had not been used since 2019 and that its review found no evidence anyone other than the researchers had accessed the data. The company said it would launch a bug bounty program. McDonald's said it was disappointed by the unacceptable vulnerability at a third-party provider. The researchers published their findings on July 9, only after the issues had been resolved.

Days later, security journalist Brian Krebs reported that a Paradox.ai developer in Vietnam had been infected with infostealer malware that exposed passwords for internal systems, many of them weak, raising further questions about the company's security practices. Paradox said that incident did not involve the McHire platform. No regulatory penalties had been announced, but the case drew wide attention as an example of weak basics undermining sophisticated AI products.

The McHire exposure highlights the risks of outsourcing sensitive functions such as hiring to vendors whose security may lag behind their product ambitions. Job seekers, who often share contact details and personal information freely, had no way to know how their data was protected. For companies, the lesson was to audit vendors for default credentials and authorization flaws; for applicants, it was a reminder to watch for recruitment scams using details from past applications.

More from the wire

More in Food & Restaurants.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.