Skip to content

Paradox.ai

Disclosed Jul 9, 20251 year agoConfirmed

Official notice

McHire AI hiring chatbot admin flaw exposed McDonald's applicant chats

Researchers found the McHire admin interface built by Paradox.ai accepted default 123456 credentials and an IDOR flaw let them reach records they said covered up to 64 million applicants. Paradox said it fixed the issue within hours and that only five candidates' records were actually viewed, all by the researchers.

What is known

People affectedNot stated in the sources we have
DisclosedJul 9, 2025
DiscoveredJun 30, 2025
AttackExposed data
Data exposedNames, Emails, Phone numbers, Employment, Messages
SectorAI · US
StatusConfirmed

Sources

Source
Would you like an IDOR with that? Leaking 64 million McDonald's job applicationsian.sh · News
Responsible Security Updateparadox.ai · The organization

Notices filed

WhereFiledPeople
ResearchtotalJul 9, 2025
History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.

Everything about Paradox.ai

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.