AI chatbot’s simple ‘123456’ password risked exposing personal data of millions of McDonald’s job applicants
安全研究人员发现通过简单密码“123456”登录麦当劳AI招聘聊天机器人McHire后,可访问6400万申请人的个人信息及聊天记录。问题迅速修复,数据未被泄露。 2025-7-11 14:47:37 Author: techcrunch.com(查看原文) 阅读量:11 收藏

Security researchers found that they could access the personal information of 64 million people who had applied for a job at McDonald’s, in large part by logging into the company’s AI job hiring chatbot with the username and password “123456.”

Ian Carroll and Sam Curry wrote in a blog post that “during a cursory security review of a few hours,” they found the password issue and another simple security vulnerability in an internal API, which allowed access to job applicants’ past conversations with the chatbot, called McHire, supplied to McDonald’s by Paradox.ai. 

The personal data seen by the researchers included applicants’ names, email addresses, home addresses, and phone numbers.

Paradox.ai wrote in a blog post that it resolved the issues “within a few hours” after the researchers’ report, and that “at no point was candidate information leaked online or made publicly available.”

The researchers’ findings were first reported by Wired.


文章来源: https://techcrunch.com/2025/07/11/ai-chatbots-simple-123456-password-risked-exposing-personal-data-of-millions-of-mcdonalds-job-applicants/
如有侵权请联系:admin#unsafe.sh