Close Menu
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

What's On

Lenovo Legion R7000 (2025) Price (04 Aug 2025) Specification & Reviews । Lenovo Laptops

4 August 2025

Honor Play 70 Plus – Price in India, Specifications (4th August 2025)

4 August 2025

A Hiker Was Missing for Nearly a Year. Then an AI System Spotted His Helmet

4 August 2025
Facebook X (Twitter) Instagram
Just In
  • Lenovo Legion R7000 (2025) Price (04 Aug 2025) Specification & Reviews । Lenovo Laptops
  • Honor Play 70 Plus – Price in India, Specifications (4th August 2025)
  • A Hiker Was Missing for Nearly a Year. Then an AI System Spotted His Helmet
  • Infinix GT 30 5G+ India Launch Confirmed for August 8; Key Specifications Revealed
  • Vivo Y04s – Price in India, Specifications (4th August 2025)
  • The Big Money and High Cost of the US Military’s On-Base Slot Machines
  • Honor Play 70 Plus With 7,000mAh Battery, Snapdragon 6s Gen 3 Chip Launched: Price, Specifications
  • Amazon Freedom Festival Sale 2025 Best-Selling Products Include Samsung Galaxy A55, iQOO Neo 10R and OnePlus Pad Go
Facebook X (Twitter) Instagram Pinterest Vimeo
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release
Subscribe
Best in TechnologyBest in Technology
Home » McDonald’s AI Hiring Bot Exposed Millions of Applicants’ Data to Hackers Who Tried the Password ‘123456’
News

McDonald’s AI Hiring Bot Exposed Millions of Applicants’ Data to Hackers Who Tried the Password ‘123456’

News RoomBy News Room10 July 20253 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email

If you want a job at McDonald’s today, there’s a good chance you’ll have to talk to Olivia. Olivia is not, in fact, a human being, but instead an AI chatbot that screens applicants, asks for their contact information and résumé, directs them to a personality test, and occasionally makes them “go insane” by repeatedly misunderstanding their most basic questions.

Until last week, the platform that runs the Olivia chatbot, built by artificial intelligence software firm Paradox.ai, also suffered from absurdly basic security flaws. As a result, virtually any hacker could have accessed the records of every chat Olivia had ever had with McDonald’s applicants—including all the personal information they shared in those conversations—with tricks as straightforward as guessing the username and password “123456.”

On Wednesday, security researchers Ian Carroll and Sam Curry revealed that they found simple methods to hack into the backend of the AI chatbot platform on McHire.com, McDonald’s website that many of its franchisees use to handle job applications. Carroll and Curry, hackers with a long track record of independent security testing, discovered that simple web-based vulnerabilities—including guessing one laughably weak password—allowed them to access a Paradox.ai account and query the company’s databases that held every McHire user’s chats with Olivia. The data appears to include as many as 64 million records, including applicants’ names, email addresses, and phone numbers.

Carroll says he only discovered that appalling lack of security around applicants’ information because he was intrigued by McDonald’s decision to subject potential new hires to an AI chatbot screener and personality test. “I just thought it was pretty uniquely dystopian compared to a normal hiring process, right? And that’s what made me want to look into it more,” says Carroll. “So I started applying for a job, and then after 30 minutes, we had full access to virtually every application that’s ever been made to McDonald’s going back years.”

When WIRED reached out to McDonald’s and Paradox.ai for comment, a spokesperson for Paradox.ai shared a blog post the company planned to publish that confirmed Carroll and Curry’s findings. The company noted that only a fraction of the records Carroll and Curry accessed contained personal information, and said it had verified that the account with the “123456” password that exposed the information “was not accessed by any third party” other than the researchers. The company also added that it’s instituting a bug bounty program to better catch security vulnerabilities in the future. “We do not take this matter lightly, even though it was resolved swiftly and effectively,” Paradox.ai’s chief legal officer, Stephanie King, told WIRED in an interview. “We own this.”

In its own statement to WIRED, McDonald’s agreed that Paradox.ai was to blame. “We’re disappointed by this unacceptable vulnerability from a third-party provider, Paradox.ai. As soon as we learned of the issue, we mandated Paradox.ai to remediate the issue immediately, and it was resolved on the same day it was reported to us,” the statement reads. “We take our commitment to cyber security seriously and will continue to hold our third-party providers accountable to meeting our standards of data protection.”

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleSamsung Galaxy Watch 8 (44mm) Online at Lowest Price in India
Next Article iPhone 17 Air Colour Options Hinted in New Leak; Could Launch in Four Shades

Related Articles

News

A Hiker Was Missing for Nearly a Year. Then an AI System Spotted His Helmet

4 August 2025
News

The Big Money and High Cost of the US Military’s On-Base Slot Machines

4 August 2025
News

What’s Inside the Tiny Miracle Food Pouches That Can Save the Lives of Starving Gazans

4 August 2025
News

High-Tech Skelly Is Here for Halloween

4 August 2025
News

The Nintendo Switch 2’s Biggest Problem Is Already Storage

3 August 2025
News

Efforts to Ground Physics in Math Are Opening the Secrets of Time

3 August 2025
Demo
Top Articles

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 2024104 Views

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202495 Views

Oppo Reno 14, Reno 14 Pro India Launch Timeline and Colourways Leaked

27 May 202582 Views

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Latest News
News

The Big Money and High Cost of the US Military’s On-Base Slot Machines

News Room4 August 2025
Phones

Honor Play 70 Plus With 7,000mAh Battery, Snapdragon 6s Gen 3 Chip Launched: Price, Specifications

News Room4 August 2025
Laptops

Amazon Freedom Festival Sale 2025 Best-Selling Products Include Samsung Galaxy A55, iQOO Neo 10R and OnePlus Pad Go

News Room4 August 2025
Most Popular

The Spectacular Burnout of a Solar Panel Salesman

13 January 2025129 Views

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 2024104 Views

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202495 Views
Our Picks

Infinix GT 30 5G+ India Launch Confirmed for August 8; Key Specifications Revealed

4 August 2025

Vivo Y04s – Price in India, Specifications (4th August 2025)

4 August 2025

The Big Money and High Cost of the US Military’s On-Base Slot Machines

4 August 2025

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us
© 2025 Best in Technology. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.