Security researchers discovered a major flaw in McDonald's AI-powered hiring platform, McHire, on June 30, 2025.
The flaw involved weak default credentials (both username and password set to 123456), allowing backend access to applicant data within 30 minutes.
As many as 64 million job applicant records were at risk of exposure, potentially leading to phishing scams, identity theft, and fraud.
McDonald's and Paradox.ai acknowledged the issue, highlighting the importance of protecting user data and implementing cybersecurity measures even with AI convenience.