Close Menu
  • Home
  • AI & Technology
  • Politics
  • Business
  • Cryptocurrency
  • Sports
  • Finance
  • Fitness
  • Gadgets
  • World
  • Marketing

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

What The Solana Open Interest Is Saying About The Cryptocurrency Right Now

March 28, 2026

Bitcoin Faces Familiar Crossroads As Midterm Cycle Turns Bearish

March 28, 2026

Elon Musk Demands Delaware Judge Be Removed from Tesla Lawsuit over LinkedIn Activity

March 28, 2026
Facebook X (Twitter) Instagram
  • Home
  • About US
  • Advertise
  • Contact US
  • DMCA
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
MNK NewsMNK News
  • Home
  • AI & Technology
  • Politics
  • Business
  • Cryptocurrency
  • Sports
  • Finance
  • Fitness
  • Gadgets
  • World
  • Marketing
MNK NewsMNK News
Home » AI Chatbot for Hiring McDonald’s Workers Exposed Millions of Applicants’ Personal Data
AI & Technology

AI Chatbot for Hiring McDonald’s Workers Exposed Millions of Applicants’ Personal Data

MNK NewsBy MNK NewsJuly 13, 2025No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email


Security researchers have uncovered glaring vulnerabilities in the “McHire” AI chatbot used by McDonald’s to hire workers, potentially exposing the personal information of approximately 64 million job applicants.

Tom’s Hardware reports that security researchers Ian Carroll and Sam Curry have discovered critical flaws in the McHire chatbot, developed by Paradox.ai for McDonald’s, which could have been exploited to access sensitive data of millions of job applicants. The chatbot, known as Olivia, is reportedly used by 90 percent of McDonald’s franchises in the United States to streamline their hiring processes.

The first vulnerability came to light when the researchers successfully guessed the password used by Paradox team members to access McHire: “123456.” This weak password allowed Carroll and Curry to gain administrator access to a test restaurant within the McHire system. While this initial access only revealed employees of Paradox.ai, it provided valuable insights into the workings of the application.

However, the real concern emerged with the discovery of a second vulnerability. An insecure direct object reference (IDOR) flaw in the McHire API enabled the researchers to access a wealth of personal information from every chat interaction involving individuals who had ever applied for a job at McDonald’s. This exposed data included names, email addresses, phone numbers, addresses, candidacy states, form inputs such as preferred shifts, and even authentication tokens that could be used to log into the consumer UI and view raw chat messages.

The scale of the potential data breach is staggering, given that Paradox had previously touted McHire’s adoption by 90 percent of McDonald’s franchises. With McDonald’s boasting a market cap of $213 billion and Paradox having raised $200 million in 2020, the use of such a weak password and the presence of the IDOR flaw raise serious questions about the companies’ commitment to data security.

Fortunately, Carroll and Curry reported the vulnerabilities to Paradox, and the company addressed the issues within a day of disclosure. However, the incident serves as a stark reminder of the importance of implementing robust security measures, especially when handling sensitive personal information.

The exposure of personal data belonging to millions of job applicants is a major concern, as it could potentially lead to identity theft, phishing attempts, or other malicious activities. It is crucial for companies, particularly those dealing with vast amounts of user data, to prioritize security and adopt stringent password policies and secure coding practices.

Read more at Tom’s Hardware here.

Lucas Nolan is a reporter for Breitbart News covering issues of free speech and online censorship.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
MNK News
  • Website

Related Posts

Elon Musk Demands Delaware Judge Be Removed from Tesla Lawsuit over LinkedIn Activity

March 28, 2026

Netflix Raises Prices Again, Gets Mocked by Rival Streaming Service

March 28, 2026

FCC Chief Brendan Carr Celebrates One Year of ‘Delete, Delete, Delete’ with 38 Pages of FCC Regulations Scrapped

March 27, 2026
Add A Comment
Leave A Reply Cancel Reply

Editors Picks

Tiger Woods arrested, charged with DUI after Florida crash

March 28, 2026

Sabalenka, Sinner keep ‘Sunshine Double’ in sight with Miami Open wins

March 27, 2026

Hasan’s pace, all-round Ali give Kings victory over Gladiators

March 27, 2026

Iranian football players hold schoolbags in solidarity with girls killed in strike on Minab school

March 27, 2026
Our Picks

What The Solana Open Interest Is Saying About The Cryptocurrency Right Now

March 28, 2026

Bitcoin Faces Familiar Crossroads As Midterm Cycle Turns Bearish

March 28, 2026

Ethereum Price Falls Below Psychological $2,000 Support — What Next?

March 28, 2026

Recent Posts

  • What The Solana Open Interest Is Saying About The Cryptocurrency Right Now
  • Bitcoin Faces Familiar Crossroads As Midterm Cycle Turns Bearish
  • Elon Musk Demands Delaware Judge Be Removed from Tesla Lawsuit over LinkedIn Activity
  • Austria is pursuing a social media ban for kids under 14
  • Ethereum Price Falls Below Psychological $2,000 Support — What Next?

Recent Comments

No comments to show.
MNK News
Facebook X (Twitter) Instagram Pinterest Vimeo YouTube
  • Home
  • About US
  • Advertise
  • Contact US
  • DMCA
  • Privacy Policy
  • Terms & Conditions
© 2026 mnknews. Designed by mnknews.

Type above and press Enter to search. Press Esc to cancel.