{"id":3613,"date":"2025-07-12T18:15:16","date_gmt":"2025-07-12T18:15:16","guid":{"rendered":"https:\/\/musictechohio.online\/site\/mcdonalds-ai-hackers\/"},"modified":"2025-07-12T18:15:16","modified_gmt":"2025-07-12T18:15:16","slug":"mcdonalds-ai-hackers","status":"publish","type":"post","link":"https:\/\/musictechohio.online\/site\/mcdonalds-ai-hackers\/","title":{"rendered":"McDonald&#8217;s Idiotic AI Hiring System Just Leaked Personal Data About Millions of Job Applicants"},"content":{"rendered":"<div>\n<div><img width=\"2400\" height=\"1260\" src=\"https:\/\/wordpress-assets.futurism.com\/2025\/07\/mcdonalds-ai-hackers.jpg\" class=\"attachment-full size-full wp-post-image\" alt=\"An embarrassing exploit just uncovered the personal data of some 64 million McDonald's applicants sitting right out in the open.\" style=\"margin-bottom: 15px;\" decoding=\"async\" fetchpriority=\"high\"><\/div>\n<p>As large language models (LLMs) become ever more integrated into the platforms that define daily life, major flaws in the software&#8217;s security capabilities are starting to show.<\/p>\n<p>McDonald&#8217;s is among the <a href=\"https:\/\/futurism.com\/companies-bragging-ai-job-applicants\">growing list<\/a> of companies that have quickly shoehorned LLM chatbots into their hiring systems, consequences be damned. Its Paradox.ai-built chatbot, which McDonald&#8217;s calls a &#8220;<a href=\"https:\/\/jobs.mchire.com\/\">virtual recruiting assistant<\/a>,&#8221; goes by the name Olivia.<\/p>\n<p>Olivia is more than happy to help applicants find jobs near them through a fake-live chat, complete with a photo of a human worker to make the whole thing that much more uncanny.<\/p>\n<p>As a chatbot, Olivia&#8217;s not that remarkable. It ushers job seekers through a maze of incomprehensible personality tests and screening questions, complete with the <a href=\"https:\/\/www.reddit.com\/r\/mildlyinfuriating\/comments\/1lo9s75\/mcdonalds_hiring_ai_is_making_me_go_insane\/\">infuriating hallucinations<\/a> one can expect to run into with an LLM.<\/p>\n<p>However, to a hacker who knows how to crack LLMs, Olivia is a treasure trove waiting to be uncovered.<\/p>\n<p>As <a href=\"https:\/\/www.wired.com\/story\/mcdonalds-ai-hiring-chat-bot-paradoxai\/\">first reported by <em>Wired<\/em><\/a>, Olivia had some astonishing security defects hiding just beneath its faux-human skin. With the right knowledge, a hacker could access the chatlogs of 64 million McDonald&#8217;s applicants, including personal details, such as full names, email addresses, phone numbers, addresses, work availability, and raw chat data.<\/p>\n<p>Olivia&#8217;s jaw-dropping weakness was discovered by cybersecurity researchers Ian Carroll and Sam Curry, who were able to break into the backend of the Paradox.ai LLM using the username and password &#8220;123456.&#8221; From there, the white hat hackers were able to access the AI company&#8217;s &#8220;test restaurant,&#8221; giving them a glimpse at how the whole thing worked.<\/p>\n<p>&#8220;It turned out we had become the administrator of a test restaurant inside the McHire system,&#8221; Carroll wrote <a href=\"https:\/\/ian.sh\/mcdonalds\">on his blog<\/a>. Since they were still confined to Paradox.ai&#8217;s testing software, the pair decided to apply for one of the\u00a0trial\u00a0postings to study the process.<\/p>\n<p>By diving into the code behind the application, they quickly found a parameter indicating their application number, 64,185,742. When they tried to follow the application directly below theirs, they came face to face with another job seeker&#8217;s personal info, <a href=\"https:\/\/dis-blog.thalesgroup.com\/security\/2019\/05\/13\/unmasking-data-masking\/\">unmasked<\/a> for the whole world to see.<\/p>\n<p>&#8220;We quickly realized this [system] allows us to access every chat interaction that has ever applied for a job at McDonald\u2019s,&#8221; Carroll wrote.<\/p>\n<p>&#8220;We immediately began disclosure of this issue once we realized the potential impact,&#8221; wrote Carroll. &#8220;Unfortunately, no disclosure contacts were publicly available and we had to resort to emailing random people.&#8221;<\/p>\n<p>&#8220;The Paradox.ai security page just says that we do not have to worry about security!&#8221; he added.<\/p>\n<p>The internal vulnerability has since been patched by Paradox, and the admin password is no longer 123456.\u00a0Still, it&#8217;s a\u00a0crystal clear demonstration of <a href=\"https:\/\/www.the-sun.com\/motors\/9888857\/driver-uses-ai-loophole-buy-new-car-1\/\">how irresponsible<\/a> some early LLM adoption has been.<\/p>\n<p><strong>More on hacking: <\/strong><a href=\"https:\/\/futurism.com\/iran-hackers-trump-emails\"><em>Iranian Hackers Threaten to Release Stolen Emails From Trump&#8217;s Inner Circle<\/em><\/a><\/p>\n<p>The post <a href=\"https:\/\/futurism.com\/mcdonalds-ai-hackers\">McDonald&#8217;s Idiotic AI Hiring System Just Leaked Personal Data About Millions of Job Applicants<\/a> appeared first on <a href=\"https:\/\/futurism.com\/\">Futurism<\/a>.<\/p>\n<\/div>\n<div style=\"margin-top: 0px; margin-bottom: 0px;\" class=\"sharethis-inline-share-buttons\" ><\/div>","protected":false},"excerpt":{"rendered":"<p>As large language models (LLMs) become ever more integrated into the platforms that define daily life, major flaws in the software&#8217;s security capabilities are starting to show. McDonald&#8217;s is among&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[182,177,1177,2607],"tags":[],"class_list":["post-3613","post","type-post","status-publish","format-standard","hentry","category-ai-chatbots","category-artificial-intelligence","category-cybersecurity","category-fast-food"],"_links":{"self":[{"href":"https:\/\/musictechohio.online\/site\/wp-json\/wp\/v2\/posts\/3613","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/musictechohio.online\/site\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/musictechohio.online\/site\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/musictechohio.online\/site\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/musictechohio.online\/site\/wp-json\/wp\/v2\/comments?post=3613"}],"version-history":[{"count":0,"href":"https:\/\/musictechohio.online\/site\/wp-json\/wp\/v2\/posts\/3613\/revisions"}],"wp:attachment":[{"href":"https:\/\/musictechohio.online\/site\/wp-json\/wp\/v2\/media?parent=3613"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/musictechohio.online\/site\/wp-json\/wp\/v2\/categories?post=3613"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/musictechohio.online\/site\/wp-json\/wp\/v2\/tags?post=3613"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}