Categories: Tech & Ai

AI chatbot’s simple ‘123456’ password risked exposing personal data of millions of McDonald’s job applicants


Security researchers found that they could access the personal information of 64 million people who had applied for a job at McDonald’s, in large part by logging into the company’s AI job hiring chatbot with the username and password “123456.”

Ian Carroll and Sam Curry wrote in a blog post that “during a cursory security review of a few hours,” they found the password issue and another simple security vulnerability in an internal API, which allowed access to job applicants’ past conversations with the chatbot, called McHire, supplied to McDonald’s by Paradox.ai. 

The personal data seen by the researchers included applicants’ names, email addresses, home addresses, and phone numbers.

Paradox.ai wrote in a blog post that it resolved the issues “within a few hours” after the researchers’ report, and that “at no point was candidate information leaked online or made publicly available.”

The researchers’ findings were first reported by Wired.



Source link

Abigail Avery

Share
Published by
Abigail Avery

Recent Posts

Tesla reportedly close to starting sales in India

Tesla is nearly ready to start selling its electric vehicles in India, according to Bloomberg…

5 minutes ago

Peter Schiff Sounds the Alarm: Bitcoin’s Rise Is a ‘Distraction’ From Silver’s Big Moment

Precious metals enthusiast and entrepreneur Peter Schiff has been spotlighting silver’s recent momentum—and taking a…

14 minutes ago

Is the BTC Rally Driven by Spot or Leveraged Demand? Glassnode Weighs In

The past 24 hours have witnessed bitcoin (BTC) record all-time highs (ATHs) again and again,…

50 minutes ago

Crypto Analyst Says Solana Rival on Cusp of Breakout, Updates Outlook on Bitcoin and Ethereum

A widely followed crypto analyst says that one rival of smart contract platform Solana (SOL)…

52 minutes ago

Yes, it’s the last day of Prime Day — don’t miss last-chance deals

We made it to day four out of four, everyone. There are now just hours…

1 hour ago

Does Hester Peirce’s statement help to advance the stocks’ tokenization trend?

Tokenization is trending, not only on X. Kraken and Robinhood already allow their users to…

2 hours ago