6 Sources
[1]
AI chatbot's simple '123456' password risked exposing personal data of millions of McDonald's job applicants | TechCrunch
Security researchers found that they could access the personal information of 64 million people who had applied for a job at McDonald's, in large part by logging into the company's AI job hiring chatbot with the username and password "123456." Ian Carroll and Sam Curry wrote in a blog post that
[2]
McDonald's AI Hiring Bot Exposed Millions of Applicants' Data to Hackers Who Tried the Password '123456'
If you want a job at McDonald's today, there's a good chance you'll have to talk to Olivia. Olivia is not, in fact, a human being, but instead an AI chatbot that screens applicants, asks for their contact information and resumé, directs them to a personality test, and occasionally makes them "go
[3]
McDonald's AI hiring chatbot exposed data of 64 million applicants with "123456" password
Serving tech enthusiasts for over 25 years. TechSpot means tech analysis and advice you can trust. Facepalm: Almost anyone who applied to work at McDonald's earlier this year may have exposed their name, phone number, email address, physical address, and other personal information. Security
[4]
McDonald's Idiotic AI Hiring System Just Leaked Personal Data About Millions of Job Applicants
Image by Paul Weaver / SOPA Images / LightRocket via Getty / Futurism As large language models (LLMs) become ever more integrated into the platforms that define daily life, major flaws in the software's security capabilities are starting to show. McDonald's is among the growing list of companies
[5]
McDonald's in hot water after AI tool with laughably weak password '123456' gets hacked, data of 64M job seekers exposed
McDonald's is facing major scrutiny after a shocking security lapse exposed sensitive data from as many as 64 million job seekers, all because of a default admin password that was as weak as it gets: "123456," as per a report. The breach was discovered in late June by security researchers Ian
[6]
McDonald's AI hiring platform "hacked" using incredibly simple password
It's no secret that nowadays, if you're looking for a new job at a big company chances are that your CV is going to be passed through an AI model before it gets to any human eyes. McDonald's has adopted the McHire system, using the chatbot Olivia to take personal information from applicants and
Share
Copy Link
Security researchers discovered critical vulnerabilities in McDonald's AI-powered hiring system, potentially exposing personal data of up to 64 million job applicants due to weak password protection and API flaws.
In a shocking revelation, security researchers Ian Carroll and Sam Curry uncovered critical vulnerabilities in McDonald's AI-powered hiring system, potentially exposing the personal data of up to 64 million job applicants
1
. The AI chatbot, named Olivia and developed by Paradox.ai, was found to have alarmingly weak security measures, including a default admin password set to "123456"2
.
Source: Futurism
During a routine security review, Carroll and Curry discovered they could easily access the backend of the McHire.com platform, which many McDonald's franchisees use for job applications
2
. The researchers found that:3
.1
.1
2
.The security lapse potentially affected millions of McDonald's job applicants, with researchers estimating access to as many as 64 million records
2
4
. This incident raises serious concerns about data protection and privacy in AI-driven hiring processes.Upon discovery, the researchers faced challenges in reporting the vulnerability due to a lack of proper security disclosure contacts at Paradox.ai
3
. However, once notified:1
.2
.2
.Related Stories

Source: TechCrunch
This incident highlights the potential risks associated with rapidly integrating AI technologies into hiring processes without adequate security measures
4
. Experts warn that such vulnerabilities could lead to targeted phishing attacks or social engineering campaigns5
.In response to the breach, Paradox.ai announced plans to:
5
.2
.McDonald's expressed disappointment with the third-party provider and emphasized its commitment to cybersecurity
2
.
Source: GameReactor
This incident serves as a stark reminder of the importance of robust security measures in AI-driven systems, especially those handling sensitive personal information. As AI continues to play an increasingly significant role in various industries, companies must prioritize security to maintain user trust and protect valuable data.
Summarized by
Navi
[1]
[3]
[4]
08 Feb 2025•Technology
29 May 2026•Technology

09 Jun 2026•Technology

1
Technology

2
Policy and Regulation

3
Technology
