AI chatbot’s simple ‘123456’ password risked exposing personal data of millions of McDonald’s job applicants

AI chatbot’s simple ‘123456’ password risked exposing personal data of millions of McDonald’s job applicants

Recent findings by security researchers have unveiled a significant vulnerability in McDonald's AI-powered hiring chatbot, potentially compromising the personal information of 64 million job applicants. The researchers, Ian Carroll and Sam Curry, discovered that they could easily access sensitive data by using the alarmingly simple username and password combination of '123456'. During their brief security assessment, the duo identified not only this password flaw but also another critical weakness in an internal API. This breach allowed them to view past conversations between applicants and the chatbot, known as McHire, which is operated by Paradox.ai. The exposed data included a wealth of personal information, such as names, email addresses, home addresses, and phone numbers of applicants. In response to the alarming findings, Paradox.ai stated that they addressed the security concerns within a few hours of the researchers' notification. They assured the public that no candidate information was leaked online or made publicly accessible. The revelations were initially reported by Wired, highlighting the urgent need for stronger security protocols in AI-driven hiring processes.

Sources : TechCrunch

Published On : Jul 11, 2025, 14:50

AI
Legal Battle Erupts as Family Blames Google’s AI for Son's Tragic Suicide

In a heartbreaking case from Florida, a father has filed a lawsuit against Google, alleging that the company's Gemini ch...

Business Today | Mar 06, 2026, 07:40
Legal Battle Erupts as Family Blames Google’s AI for Son's Tragic Suicide
AI
Anthropic to Contest Pentagon's Supply Chain Risk Designation in Court

Dario Amodei, CEO of Anthropic, announced on Thursday that the AI company plans to legally contest the Defense Departmen...

TechCrunch | Mar 06, 2026, 01:45
Anthropic to Contest Pentagon's Supply Chain Risk Designation in Court
Cybersecurity
Ex-Google Executive Secures $38 Million to Combat Hidden Security Flaws

Fig Security, a new startup co-founded by a former executive from Google Cloud, has recently exited stealth mode after s...

Business Insider | Mar 06, 2026, 10:05
Ex-Google Executive Secures $38 Million to Combat Hidden Security Flaws
AI
Anthropic Takes Legal Stand Against Defense Department's Supply Chain Risk Label

Anthropic is preparing to legally contest a recent classification by the United States Department of War that identifies...

Business Today | Mar 06, 2026, 03:45
Anthropic Takes Legal Stand Against Defense Department's Supply Chain Risk Label
Cybersecurity
Privacy Concerns Emerge as Meta Workers View Sensitive Footage from Ray-Ban Smart Glasses

Meta's commitment to user privacy is facing intense criticism after a recent report revealed that employees at a subcont...

Ars Technica | Mar 05, 2026, 23:40
Privacy Concerns Emerge as Meta Workers View Sensitive Footage from Ray-Ban Smart Glasses
View All News