Close Menu
  • Home
  • AI & Technology
  • Politics
  • Business
  • Cryptocurrency
  • Sports
  • Finance
  • Fitness
  • Gadgets
  • World
  • Marketing

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

‘World’s Oldest Baby’ Born from 30-Year-Old Frozen Embryo

August 2, 2025

Exchanges Receive 21,400 Bitcoin At A Loss From Short-Term Holders

August 2, 2025

Spot Ethereum ETFs Set A New Record In July With $5.4 Billion Monthly Inflow

August 2, 2025
Facebook X (Twitter) Instagram
  • Home
  • About US
  • Advertise
  • Contact US
  • DMCA
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
MNK NewsMNK News
  • Home
  • AI & Technology
  • Politics
  • Business
  • Cryptocurrency
  • Sports
  • Finance
  • Fitness
  • Gadgets
  • World
  • Marketing
MNK NewsMNK News
Home » AI Chatbot for Hiring McDonald’s Workers Exposed Millions of Applicants’ Personal Data
AI & Technology

AI Chatbot for Hiring McDonald’s Workers Exposed Millions of Applicants’ Personal Data

MNK NewsBy MNK NewsJuly 13, 2025No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email


Security researchers have uncovered glaring vulnerabilities in the “McHire” AI chatbot used by McDonald’s to hire workers, potentially exposing the personal information of approximately 64 million job applicants.

Tom’s Hardware reports that security researchers Ian Carroll and Sam Curry have discovered critical flaws in the McHire chatbot, developed by Paradox.ai for McDonald’s, which could have been exploited to access sensitive data of millions of job applicants. The chatbot, known as Olivia, is reportedly used by 90 percent of McDonald’s franchises in the United States to streamline their hiring processes.

The first vulnerability came to light when the researchers successfully guessed the password used by Paradox team members to access McHire: “123456.” This weak password allowed Carroll and Curry to gain administrator access to a test restaurant within the McHire system. While this initial access only revealed employees of Paradox.ai, it provided valuable insights into the workings of the application.

However, the real concern emerged with the discovery of a second vulnerability. An insecure direct object reference (IDOR) flaw in the McHire API enabled the researchers to access a wealth of personal information from every chat interaction involving individuals who had ever applied for a job at McDonald’s. This exposed data included names, email addresses, phone numbers, addresses, candidacy states, form inputs such as preferred shifts, and even authentication tokens that could be used to log into the consumer UI and view raw chat messages.

The scale of the potential data breach is staggering, given that Paradox had previously touted McHire’s adoption by 90 percent of McDonald’s franchises. With McDonald’s boasting a market cap of $213 billion and Paradox having raised $200 million in 2020, the use of such a weak password and the presence of the IDOR flaw raise serious questions about the companies’ commitment to data security.

Fortunately, Carroll and Curry reported the vulnerabilities to Paradox, and the company addressed the issues within a day of disclosure. However, the incident serves as a stark reminder of the importance of implementing robust security measures, especially when handling sensitive personal information.

The exposure of personal data belonging to millions of job applicants is a major concern, as it could potentially lead to identity theft, phishing attempts, or other malicious activities. It is crucial for companies, particularly those dealing with vast amounts of user data, to prioritize security and adopt stringent password policies and secure coding practices.

Read more at Tom’s Hardware here.

Lucas Nolan is a reporter for Breitbart News covering issues of free speech and online censorship.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
MNK News
  • Website

Related Posts

‘World’s Oldest Baby’ Born from 30-Year-Old Frozen Embryo

August 2, 2025

AI Can’t Keep a Secret: Sensitive Conversations with ChatGPT Show Up on Google Searches

August 2, 2025

Exclusive — Rep. Jim Jordan: UK, EU Issuing ‘Direct Attack’ on Free Speech, Like Biden Administration

August 1, 2025
Add A Comment
Leave A Reply Cancel Reply

Editors Picks

SA want promising T20 batters to show potential – Sport

August 2, 2025

Gauff fights back to advance in Canada, Medvedev crashes out – Sport

August 2, 2025

Santner-inspired New Zealand beat Zimbabwe in first Test – Sport

August 2, 2025

Pakistan, Afghanistan, UAE to play T20I tri-series in Sharjah – Sport

August 1, 2025
Our Picks

Exchanges Receive 21,400 Bitcoin At A Loss From Short-Term Holders

August 2, 2025

Spot Ethereum ETFs Set A New Record In July With $5.4 Billion Monthly Inflow

August 2, 2025

Ethereum New Addresses Surge To Nearly 257K In A Day, Matching 2017 And 2021 Bull Markets

August 2, 2025

Recent Posts

  • ‘World’s Oldest Baby’ Born from 30-Year-Old Frozen Embryo
  • Exchanges Receive 21,400 Bitcoin At A Loss From Short-Term Holders
  • Spot Ethereum ETFs Set A New Record In July With $5.4 Billion Monthly Inflow
  • YouTube is testing Instagram-style collabs
  • AI Can’t Keep a Secret: Sensitive Conversations with ChatGPT Show Up on Google Searches

Recent Comments

No comments to show.
MNK News
Facebook X (Twitter) Instagram Pinterest Vimeo YouTube
  • Home
  • About US
  • Advertise
  • Contact US
  • DMCA
  • Privacy Policy
  • Terms & Conditions
© 2025 mnknews. Designed by mnknews.

Type above and press Enter to search. Press Esc to cancel.