One might be surprised to learn that McDonald’s job applicants must now chat with an AI bot as part of the application process. One would probably be even more surprised to learn that the password protecting access to that bot’s backend was one of the most obvious and terrible that could have possibly been chosen, meaning that up to 64 million job application records may have been exposed to hackers that tried it.
The administrator account password protecting the AI bot platform hosted at “mchire.com” was “123456”, as discovered by security researchers Ian Carroll and Sam Curry. The included records include the conversation exchanges that applicants have with the McHire bot as well as basic contact information such as full names, addresses and phone numbers.
McDonald’s AI bot compromised with generic username/password combo
While the AI bot did not appear to have access to applicant Social Security numbers or anything similarly sensitive, the message exchanges include questions about specific job locations and shift availability. The McHire process also includes a personality test administered by the third party “Traitify.com” before the applicant is handed off to the “Olivia” chatbot system for potential future conversations with franchise owners or hiring personnel.
The McHire AI bot was created by Paradox.ai, which claims that 90% of McDonald’s franchisees make use of it in their hiring pipeline. Hacking it apparently did not require any amount of technical knowledge at all; the researchers say that it could be done by simply navigating to the McHire login page, clicking on a link for “Paradox team members” near the bottom of the page, and entering the “123456 / 123456” combination as a login. Interestingly, trying “admin” as a user name instead did not work.
The researchers say that this administrative access allows one to pull up the chat history and contact info of every applicant that has ever interacted with the AI bot. The McHire platform has been in use since 2019, but was first used solely for corporate-owned restaurant locations for a time before being gradually rolled out to franchisees in the US, Canada, the UK and Ireland.
The researchers disclosed the AI bot’s vulnerability to Paradox.ai and McDonald’s on June 30, and note that the credentials had stopped working as of later that day. But there is no way to know how long this easy-to-guess password was in place, or how many other intruders might have come across it. McDonald’s responded to the publication of the story by saying it has no indication that any other third parties accessed the administrator account in this way, and also stated that it will be implementing a bug bounty program to catch future errors of this nature. Paradox.ai said that it will conduct more frequent security audits going forward.
“Dystopian” application process prompted probing
The security researchers say their interest in the AI bot was piqued after seeing multiple threads on Reddit documenting “crazy” responses during the application process and complaints about it being hard to deal with. Their original intent was to see if it could be compromised with prompt injection attacks, and they did not stumble across the poorly protected account until after that avenue of approach did not pan out.
One limitation to the AI bot attack is that there is not a particularly good way to search applications for names, or even separate them by location. The researchers noticed that they could create an application for themselves once logged in, which then generated a unique application number; incrementally changing this number granted access to other people’s applications.
The researchers note that this access could have been used to determine when applicants who were ultimately hired might be away from home, and also could have been leveraged against those still waiting for a call-back as a means of stealing more damaging personal and financial information from them.
There have long been complaints about personality tests and other onerous elements being added to the applications for low-wage and “unskilled” positions in industries such as fast food and retail, but the use of AI bots is a relatively new twist. A survey conducted earlier in the year by Resume Builder found that only 40% of responding companies used AI chatbots to communicate with employees in any way, and just 23% use it as part of the job interview process. However, these numbers are expected to grow quickly with 82% already having onboarded AI tools to at minimum scan and filter resumes.
Basic security oversights seem to be rife in this area. There has already been a rash of data breaches in 2025 involving hiring platforms and millions of exposed records, most thus far involving a misconfigured database left facing the open internet. These include a very recent breach at LiveCareer that exposed the contents of 5.1 million resumes dating back to 2016, and an exposure at European job platform beWanted that involved national ID numbers in some cases. Applicant tracking system TalentHook also saw 26 million records exposed due to an Azure Cloud misconfiguration.
Desired Effect CEO Evan Dornbush, former NSA cybersecurity expert, thinks that the seemingly cavalier attitude toward PII handling in the job application space is likely owed to companies rapidly onboarding new screening tools without being adequately familiar with them: “While we all love a good burger, nobody wants their personal data served up with a side of cybersecurity negligence. Ironic McDonald’s is getting fried in tech circles, and rightfully so. This incident is a prime example of what happens when organizations deploy technology without having an understanding about how it works or how it can be operated by untrusted users. Brands need to be thinking about vulnerabilities from the ground up, not just as an afterthought. This scenario underscores that reactive security is no longer enough. With AI systems handling millions of sensitive data points organizations must invest in understanding and mitigating pre-emergent threats, or they’ll find themselves playing catch-up, with their customers’ trust on the line.”
William Leichter, Senior Officer at PointGuard AI, agrees: “This problem isn’t unique to AI—it’s a recurring pattern with every so-called ‘game-changing’ technology. The hype cycle drives organizations to deploy fast, chasing immediate gains while sidelining seasoned security professionals. We saw the same thing during the early rush to the cloud a decade ago, when developers uploaded sensitive data to Amazon S3 buckets without basic password protection. Now, it’s AI’s turn: tools are being rolled out hastily, with immature controls and sloppy practices. The lesson is clear—slow down and secure it properly. Maybe incidents like this one will finally serve as the wake-up call we need.”
Darren James, Senior Product Manager at cybersecurity firm Specops Software, comments on what this says about ongoing password hygiene issues: “Even experienced IT developers make mistakes when it comes to passwords. And if these guys make mistakes that put their customers at risk, it’s even more likely that your end users will make the same errors, or make poor password choices, reuse passwords, and not follow best practice at all when it comes to cyber security and hygiene. As such, organizations need to make sure that they adopt “fit for purpose” password policies wherever they can, to make sure that passwords, or even better passphrases, are simple to use, have not previously been breached, are strong enough for their intended use, and can be detected and acted upon should they become breached. On top of that, companies should use systems that can provide feedback to users to guide them about what is a good password, and wherever possible make use of a strong biometric 2nd factor. All organizations should not just bury their heads in the sand about this threat. They should act quickly to have a good understanding of where they are right now when it comes to their password security posture.”

