uniladtech homepage
  • News
    • Tech News
    • AI
  • Gadgets
    • Apple
    • iPhone
  • Gaming
    • Playstation
    • Xbox
  • Science
    • News
    • Space
  • Streaming
    • Netflix
  • Vehicles
    • Car News
  • Social Media
    • WhatsApp
    • YouTube
  • Advertise
  • Terms
  • Privacy & Cookies
  • LADbible Group
  • LADbible
  • UNILAD
  • SPORTbible
  • GAMINGbible
  • Tyla
  • FOODbible
  • License Our Content
  • About Us & Contact
  • Jobs
  • Latest
  • Archive
  • Topics A-Z
  • Authors
Facebook
Instagram
X
TikTok
Snapchat
WhatsApp
Submit Your Content
McDonald's AI hiring bot exposes data of 64,000,000 applicants after hackers guess 'stupid' password
Home>News>Tech News
Published 15:16 14 Jul 2025 GMT+1

McDonald's AI hiring bot exposes data of 64,000,000 applicants after hackers guess 'stupid' password

The fast food giant isn't lovin' it

Tom Chapman

Tom Chapman

google discoverFollow us on Google Discover
Featured Image Credit: TonyBaggett via Getty
AI
Cybersecurity
Tech News

Advert

Advert

Advert

Ronald McDonald has been left a little red-faced, as McDonald's has been hit by a seemingly major data breach that could be down to some dodgy artificial intelligence. Like it or not, AI is in our lives more than ever in 2025. While some are critical of its potential to wipe humanity off the face of the Earth, others are more worried about the immediate dangers of it costing real-life humans their jobs.

We've already seen Microsoft get slammed for letting some 9,000 jobs go while investing $80 billion in AI, while the likes of customer service representatives, data entry inputters, and writers (oh great), are the most at risk of being replaced by AI. Our worries about losing our jobs to artificial intelligence could also also extend to those on hiring teams, with McDonald's seemingly streamlining the process with AI.

After all, one little chatbot can easily sift through thousands of CVs in seconds. As reported by Wired, the fast food giant has accidentally exposed the data of some 64 million applicants thanks to an AI fumble.

The McDonald's hiring process has been called into question (Gary Hershorn / Contributor / Getty)
The McDonald's hiring process has been called into question (Gary Hershorn / Contributor / Getty)

Advert

When applying for a job at McDonald's in 2025, you'll likely be greeted by Olivia. Instead of being a friendly face from the hiring team, she's an AI chatbot that asks for your details, takes your résumé, and makes you take a personality test. There were already complaints that Olivia isn't exactly top of her game, apparently driving applicants 'insane' because she can't understand simple instructions.

Researchers have found that Olivia's overlords at Paradox.ai had a major security flaw that was a hacker's goldmine. Apparently, it's as easy as guessing that an administrator account's username as ‘admin’ and password as '123456'. This gives potential bad actors access to every chat Olivia had, meaning some very personal details could've been exposed.

Security researchers Ian Carroll and Sam Curry discovered how easy it was to hack the backend of Olivia on McHire.com, noting there were several web-based vulnerabilities that included "one laughably weak password." Up to 64 million records were there, including the names of applicants, their email addresses, and phone numbers.

Carroll says he only looked into things when he noticed that McDonald's was trying to AI-ify its hiring process: "I just thought it was pretty uniquely dystopian compared to a normal hiring process, right? And that's what made me want to look into it more.



"So I started applying for a job, and then after 30 minutes, we had full access to virtually every application that's ever been made to McDonald's going back years."

Paradox.ai directed wired to a blog post about Carroll and Curry’s hack, confirming a security update but reassuring us that the information "was not accessed by any third party” other than the pair.

Paradox.ai’s chief legal officer, Stephanie King, told Wired: "We do not take this matter lightly, even though it was resolved swiftly and effectively. We own this."

McDonald's also responded and kept the blame on Paradox as it wrote: "We’re disappointed by this unacceptable vulnerability from a third-party provider, Paradox.ai. As soon as we learned of the issue, we mandated Paradox.ai to remediate the issue immediately, and it was resolved on the same day it was reported to us.

"We take our commitment to cyber security seriously and will continue to hold our third-party providers accountable to meeting our standards of data protection.”

Even though it's not the most sensitive information, Curry concluded: "Had someone exploited this, the phishing risk would have actually been massive. It's not just people's personally identifiable information and résumés. It's that information for people who are looking for a job at McDonald's, people who are eager and waiting for emails back."

  • Kevin O'Leary forced to slash his 'atomic bomb' AI data center by 75% after massive backlash
  • Anthropic release Claude Mythos to the public despite 'risks' of super powerful AI
  • Anthropic’s hyped 'Claude Mythos' AI is reportedly launching this week under a different name
  • Kevin O'Leary's Utah AI data centre could emit the heat of '23 atomic bombs' every single day

Choose your content:

20 mins ago
27 mins ago
an hour ago
  • hapabapa/Getty Images
    20 mins ago

    The one technical rule that saved WhatsApp from the UK’s under-16 social media ban

    UK bans social media use for all children under the age of 16

    News
  • andresr / Getty
    27 mins ago

    Police chief calls for phone companies to add 'kill switch' to every phone

    This feature would render devices completely unusable

    News
  • Gilbert Flores/2026GG / Contributor / Getty
    an hour ago

    White House deletes TikTok video after Ariana Grande calls out 'barbaric' use of her music

    The White House video disappeared after the singer stepped in

    News
  • STR/NurPhoto via Getty Images
    an hour ago

    Signal issues urgent warning over 'dystopian' new phone privacy laws

    This comes as the UK bans social media for under 16s

    News