In late June 2025, security researchers Ian Carroll and Sam Curry spent a few hours looking at McHire, the recruitment platform used by most McDonald's franchisees, where applicants chat with an AI assistant called Olivia built by Paradox.ai. They found two problems. The restaurant administration interface had a small sign-in link for "Paradox team members," and it accepted the username 123456 and password 123456, opening an administrator account for a test restaurant. From there, an internal API returned applicant records by a sequential ID, so decreasing the number showed other applicants' names, contact details, application history and an authentication token for their account. The researchers estimated more than 64 million applicant records were reachable. They reported the issues on 30 June; the credentials stopped working that evening, and Paradox.ai confirmed the fixes the next day. Paradox.ai said the test account had not been used since 2019, that no one other than the researchers accessed it, and that they viewed five candidates' information.
Key takeaways
- A dormant Paradox.ai test administrator account accepted the credentials 123456 / 123456, bypassing the McDonald's single sign-on route.
- An insecure direct object reference (IDOR) in an internal API let that account read any applicant's record by changing an ID.
- The researchers estimated more than 64 million applicant records were reachable, including tokens to log in as candidates.
- Paradox.ai said only the researchers accessed the account, that five candidates' information was viewed, and fixed both issues within a day.
- The identity lesson: forgotten test and admin accounts with default credentials are identities too, and they need an owner, MFA and decommissioning.
At a glance
| Organisations | Paradox.ai (maker of the Olivia hiring assistant); McDonald's (McHire platform used by franchisees) |
|---|---|
| When | Found and reported 30 June 2025; fixed by 1 July 2025; Paradox.ai statement 9 July 2025 |
| Attacker | None known. Found by researchers Ian Carroll and Sam Curry |
| Entry point | A test administrator account on the McHire admin interface with the default credentials 123456 / 123456 |
| Identities abused | A dormant test administrator account; candidate authentication tokens returned by the vulnerable API |
| Impact | Researchers estimated more than 64 million applicant records were reachable; Paradox.ai says five candidates' data was viewed, by the researchers only |
| Category | NHI, Agentic AI and AI agents. Incident class: confirmed NHI breach (default credentials used by researchers to reach applicant data) |
What happened
Carroll and Curry started looking at McHire after seeing Reddit complaints about the Olivia chatbot giving nonsensical answers. The restaurant owner sign-in page pushed McDonald's staff to single sign-on, but "there is a smaller link for "Paradox team members" that caught our eye," they wrote. "Without much thought, we entered "123456" as the username and "123456" as the password and were surprised to see we were immediately logged in!" They had become the administrator of a test restaurant whose employees were all Paradox.ai staff.
From that account they could view applicant conversations. An API to fetch candidate information, PUT /api/lead/cem-xhr, took a lead_id parameter; their own test application was around 64,185,742. "We tried decrementing this number, and were immediately faced with PII from another McDonald's applicant," they wrote. Records included names, email addresses, phone numbers and addresses, every form input the candidate had submitted, and an "Auth token to log into the consumer UI as that user, leaking their raw chat messages." Together, the researchers said, the two issues would let "anyone else with a McHire account and access to any inbox" retrieve data on more than 64 million applicants.
They disclosed to Paradox.ai and McDonald's at 5:46 p.m. ET on 30 June; by 7:31 p.m. "Credentials are no longer usable to access the app," and on 1 July Paradox.ai confirmed the issues were resolved. In its statement, reported by KrebsOnSecurity, Paradox.ai said the test account "had not been logged into since 2019 and frankly, should have been decommissioned," and that the researchers "only viewed and downloaded five chats in total that had candidate information within." KrebsOnSecurity separately found that a Paradox.ai administrator's device had been infected with infostealer malware in June 2025, exposing credentials for internal and client accounts; Paradox.ai said few of those passwords were still valid.
Timeline
| Date | Event |
|---|---|
| 2019 | The test administrator account is last used, according to Paradox.ai. |
| 30 June 2025 | The researchers disclose the issues; the default credentials stop working within two hours. |
| 1 July 2025 | Paradox.ai confirms the issues are resolved. |
| 9 July 2025 | Paradox.ai publishes its statement. |
| 11 July 2025 | CSO Online reports the findings. |
How it happened: the identity attack path
- Forgotten account. A test administrator account from 2019 was never decommissioned.
- Default credentials. It used 123456 as both username and password, with no MFA.
- SSO bypass. A separate sign-in link for vendor staff avoided McDonald's single sign-on.
- Broken authorisation. The API returned any applicant's record by ID, without checking the account's entitlement.
- Token exposure. Records included tokens to log in as the candidate.
Impact
- Reachable: more than 64 million applicant records, by the researchers' estimate.
- Accessed: five candidates' information, by the researchers only, according to Paradox.ai.
- Misuse: none reported.
What this means for NHI governance
The account at the centre of this finding was not a real user. It was a test identity created by a vendor, forgotten for six years, still active and still holding administrator rights on a production system. Accounts like this are common: created for testing, integration or support, owned by nobody, and invisible to the reviews that cover employees. When they also use default credentials and a login path outside single sign-on, they become the easiest way in.
AI assistants add scale to that risk. Olivia collected conversations from tens of millions of applicants into one platform, so one weak account and one missing authorisation check exposed all of them. Every identity with access to an AI system's data, including vendor test accounts, needs an owner, strong authentication and a planned end date. See our NHI Ownership Guide and Third-Party Access Guide.
Recommendations
- Find and remove dormant test and admin accounts. Review accounts that have not logged in for months. See the NHI Ownership Guide.
- Force every login through SSO and MFA. Remove side entrances for vendor staff. See the Identity Provider and SSO Security Guide.
- Ban default and trivial passwords. Check credentials against common and breached password lists. See the Password Security Guide.
- Enforce object-level authorisation in APIs. Every request should check that the caller may see that record. See the Authorisation Models Guide.
- Govern vendor access to your data. Include vendor accounts on your platforms in access reviews. See the Third-Party Access Guide.
Frequently asked questions
What was the McHire vulnerability?
A Paradox.ai test administrator account on McDonald's McHire platform used the credentials 123456 / 123456, and an internal API returned any applicant's record by ID. Together they could expose applicant data at scale.
Were 64 million McDonald's applicants' data stolen?
No theft has been reported. The researchers estimated more than 64 million records were reachable. Paradox.ai says only the researchers accessed the account and that five candidates' information was viewed.
How quickly was it fixed?
The credentials stopped working within two hours of disclosure on 30 June 2025, and Paradox.ai confirmed all issues were resolved on 1 July.
Related NHI Mgmt Group resources
HPE Aruba Hard-Coded Credentials 2025 · OmniGPT Breach Claim 2025 · NHI Ownership Guide · Third-Party Access Guide · Password Security Guide
How NHI Mgmt Group can help
Test, vendor and service accounts outlive the projects that created them. We help teams find forgotten accounts, assign owners and remove the ones nobody needs. See our NHI and AI agent security training.
References
- Ian Carroll and Sam Curry: Would you like an IDOR with that? Leaking 64 million McDonald's job applications (July 2025)
- CSO Online: McDonald's AI hiring tool's password '123456' exposed data of 64M applicants (11 July 2025)
- Tom's Hardware: McDonald's McHire bot exposed personal information of 64M people by using '123456' as a password (13 July 2025)
- KrebsOnSecurity: Poor Passwords Tattle on AI Hiring Bot Maker Paradox.ai (July 2025)