'123456': How an AI Hiring Bot Exposed 64 Million McDonald's Applicants
Researchers Ian Carroll and Sam Curry logged into the McHire admin panel with '123456/123456' and walked out with up to 64 million applicant records. The breach is the first major hospitality-AI security failure to become a public story — and it's not really about McDonald's.
I was a third of the way through a Hinge Health deck on Wednesday morning when the McHire story hit my inbox, and I closed the deck. Two security researchers — Ian Carroll and Sam Curry — had spent thirty minutes poking at the McDonald’s job application chatbot and walked out with up to 64 million applicant records. The credential that let them in was 123456/123456. The vendor sitting behind the chatbot was Paradox.ai, a hiring-automation company most restaurant operators have never heard of and almost certainly have a contract with via someone they franchise from.
Here is the contrarian read I want to put on the table before the news cycle gets to it: this is not a McDonald’s story. It is the first major hospitality-AI security failure to become a public story, and the lesson is for every operator who bolted an AI vendor onto HR last year without a security review. The brand on the press release is incidental. The supplier — and the supplier model — is the news.
The thirty-minute breach
Carroll and Curry disclosed their findings on July 9, with TechCrunch lining up a detailed write-up of the McHire vulnerability and Malwarebytes following with a parallel explainer on the McHire applicant data exposure. The mechanics are almost insulting:
- The McHire chatbot — branded internally as Olivia, built and operated by Paradox.ai — has an admin panel for franchisees and corporate recruiters.
- The researchers tried the obvious default: username 123456, password 123456. It worked. The account belonged to a Paradox test tenant that was never disabled.
- Once inside, an insecure direct object reference (an IDOR — change the candidate ID in the URL, get a different candidate’s record) let them iterate through applicant IDs. The exposed payload included names, email addresses, phone numbers, addresses, and the chat transcripts the candidates had with the bot.
Carroll told TechCrunch the upper bound on the exposure was roughly 64 million records, going back several years. Paradox.ai has since said it does not believe the test account was accessed by anyone other than the researchers, and McDonald’s pointed the press at Paradox as the third-party operator. Both statements are technically true. Neither is consolation.
There are two failures stacked here, and they are not equally interesting. The default-password failure is the headline; it makes the story tellable. The IDOR is the actual problem. The first is a junior engineer’s mistake. The second is an architectural one — an authorization model that trusted any logged-in admin to see any candidate. The chatbot did not need to be AI for the IDOR to exist. The reason an AI vendor wrote it is that hospitality is currently buying AI vendors faster than it is buying anything else, and the engineering bench writing the auth layer is whatever Paradox could staff during a 2023-2024 hiring sprint.
Why this lands on hospitality specifically
Restaurant operators have a particular exposure here that other industries don’t, and it is worth saying out loud.
Quick-service and fast-casual brands receive enormous volumes of applications relative to other employers — McDonald’s reportedly processes north of a million U.S. applications a year — and almost all of that intake is now mediated by a third-party AI vendor. Paradox is the big one. There are at least a dozen others. The applicants are disproportionately young, disproportionately first-job, and disproportionately in protected demographic categories where a leaked phone number and address is not an annoyance but an actual safety problem. The data is sensitive in a way that, say, a leaked beverage-mix report is not.
The contract structure compounds it. Most of these AI hiring vendors are sold to corporate, deployed to franchisees, and audited by neither. The franchisee operator signing a quarterly check to Paradox almost certainly has not seen a SOC 2 report, has no idea what their data retention policy is, and would be surprised to learn that the data of every candidate who applied to their three Whataburger locations sits in a tenant that shares infrastructure with every other Paradox customer. A forthcoming May piece on how the EU AI Act will land in restaurant operations makes a related point: the regulators who actually understand AI procurement are not in the U.S. yet, and the operator-side governance gap is going to bite somewhere — it just happened to bite McHire first.
Mark this as my interpretation rather than reporting: I think the McHire disclosure is going to do for hospitality AI procurement what the 2013 Target breach did for retail vendor management. Not immediately. But the next time a restaurant CTO walks into a board meeting with an AI vendor RFP, somebody is going to mention “the McDonald’s thing,” and the conversation is going to slow down. That is, on balance, a good outcome.
The vendor question operators have to answer this week
If you are running an operation of any size and you have an AI vendor touching applicants, employees, guest data, or payments — which is most of you — there are three questions you should be able to answer by Friday:
- Who is the vendor, and which of your data classes do they hold? Not the integration partner. The actual data processor. For HR tools this is rarely the company on the invoice; it is often a subcontractor two layers down.
- Have you seen their last penetration test report and their authorization model documentation? The IDOR in McHire would have surfaced in either. If your vendor will not share these, that is your answer.
- What is the blast radius if their test tenant is compromised? “We don’t know” is a legitimate first-pass answer. It is not a legitimate second-pass answer.
The point is not that AI vendors are uniquely unsafe. The point is that they were procured during a window — broadly, late 2023 through 2024 — when operators were so worried about being left behind on AI that the standard vendor-risk checklist got skipped. An upcoming May piece on Chipotle’s AI stack and the build-versus-buy question walks through one operator’s attempt to answer exactly this question; the McHire story is the cost of not answering it.
What I expect to happen next
I expect Paradox to release a longer statement before the end of the week with a remediation timeline and, probably, a third-party security audit commitment. I expect at least one state attorney general — California or Illinois are the obvious candidates — to open an inquiry. I expect a class action by mid-August, which will mostly be theater but will surface useful documents in discovery. I do not expect McDonald’s corporate to change vendors. I do expect some number of franchisee groups to ask, for the first time, why they cannot.
The thing I will be watching is whether the broader AI premium operators have been paying for hiring automation — a forthcoming May piece lays out the case against the AI premium — survives a real conversation about security cost. The math on Paradox-style vendors looked very different on July 8 than it does on July 9. It will look different again on July 10. None of that is McDonald’s fault. All of it is everyone’s problem.
— Hana edits the newsroom for TableTransfers. Tips: [email protected].
The Voice Agent Maturity Curve
mise
·12 min read
The Four Margins of a Restaurant
mise
·14 min read
The AI Premium in Hospitality M&A: Broker Story or Real Number?
the bottom line
·9 min read
What the DoorDash/SevenRooms Deal Actually Buys
the bottom line
·11 min read