Paradox.ai
Disclosed Jul 9, 20251 year agoConfirmed
McHire AI hiring chatbot admin flaw exposed McDonald's applicant chats
Researchers found the McHire admin interface built by Paradox.ai accepted default 123456 credentials and an IDOR flaw let them reach records they said covered up to 64 million applicants. Paradox said it fixed the issue within hours and that only five candidates' records were actually viewed, all by the researchers.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Jul 9, 2025 |
| Discovered | Jun 30, 2025 |
| Attack | Exposed data |
| Data exposed | Names, Emails, Phone numbers, Employment, Messages |
| Sector | AI · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Would you like an IDOR with that? Leaking 64 million McDonald's job applicationsian.sh · News | News |
| Responsible Security Updateparadox.ai · The organization | The organization |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Jul 9, 2025 |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.