The title has been changed to reflect that they are applications on the job chatbot rather than 64 million distinct candidates.
A flaw in McDonald’s chatbot job application platform, McHire, was found by cybersecurity experts to expose the conversations of over 64 million job applicants nationwide.
Security researchers Ian Carroll and Sam Curry identified the vulnerability when they observed that the admin panel of the ChatBot used a test franchise that was secured with weak credentials of “123456” for the login name and “123456” for the password.
About 90% of McDonald’s franchisees use McHire, which is powered by Paradox.ai and uses a chatbot named Olivia to take applications. In addition to providing their names, home addresses, phone numbers, email addresses, and availability, applicants must also finish a personality test as part of the hiring process.
After logging in, the researchers applied for a position at the test franchise to observe how the procedure operated read more ‘123456’ password exposed chats for 64 million McDonald’s job chatbot applications.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
