McDonald's AI-powered hiring platform McHire exposed sensitive data of 64 million job applicants due to a default admin password '123456' and insecure API vulnerabilities discovered by security researchers in June 2025.
In late June 2025, security researchers Ian Carroll and Sam Curry discovered critical vulnerabilities in McDonald's AI-powered hiring platform McHire, which uses an automated recruiter bot called Olivia created by Paradox.ai. The researchers found that the administrative interface accepted default credentials '123456' for both username and password, granting immediate access to live administrative dashboards rather than just test environments. Additionally, they discovered an insecure direct object reference (IDOR) vulnerability in an internal API that allowed access to applicant data by simply changing ID parameters. This combination of flaws potentially exposed sensitive personal information of up to 64 million job seekers, including chat histories with the AI bot, contact information, shift preferences, personality test results, and authentication tokens. The vulnerabilities were discovered during a security review prompted by Reddit user complaints about the bot's nonsensical answers. Upon disclosure on June 30, 2025, both McDonald's and Paradox.ai responded within an hour, disabling default credentials and securing the endpoint by July 1. Paradox.ai stated that only five candidate records were actually viewed by the researchers and no data was leaked publicly or accessed by malicious third parties.
Domain classification, causal taxonomy, severity scores, and national security assessments were LLM-classified and may contain errors.
AI systems that memorize and leak sensitive personal data or infer private information about individuals without their consent. Unexpected or unauthorized sharing of data and information can compromise user expectation of privacy, assist identity theft, or cause loss of confidential intellectual property.
Human
Due to a decision or action made by humans
Unintentional
Due to an unexpected outcome from pursuing a goal
Post-deployment
Occurring after the AI model has been trained and deployed