Sev0AI security incidents, tracked

All incidents / Leaky AI product

McDonald's AI hiring chatbot exposed up to 64 million applicants via password '123456'

McDonald's (Paradox.ai), disclosed Jul 2025. Leaky AI product Data exposed High

Researchers logged into the admin backend of McHire, McDonald's AI hiring chatbot built by Paradox.ai, using the default credentials 123456, then found they could step through applicant records by ID. Names, emails, phone numbers and chat logs for up to 64 million applicants were reachable. Paradox fixed it within hours and said only a handful of records were accessed.

Disclosed
Jul 2025
Organization
McDonald's (Paradox.ai)
Vendor
Unknown
Product
McHire (Olivia)
Kind of AI
Chatbot
AI's role
AI was the target
How it happened
Leaky AI product: App flaw
Harm
Data exposed
Data involved
Personal data, Chat logs
Reach
One organization
Records
64,000,000
Severity
High
Model at fault
No
Status
Confirmed
Country
US

Sources

  1. https://www.csoonline.com/article/4020919/mcdonalds-ai-hiring-tools-password-123456-exposes-data-of-64m-applicants.html
  2. https://krebsonsecurity.com/2025/07/poor-passwords-tattle-on-ai-hiring-bot-maker-paradox-ai/
  3. https://incidentdatabase.ai/cite/1179/

Related incidents

Data for this record: incidents.json. Cite as: Sev0, "McDonald's AI hiring chatbot exposed up to 64 million applicants via password '123456'", https://sev0.fyi/incidents/2025-07-01-mchire-paradox-default-password/