Get the latest tech news

Burger King hacked, attackers 'impressed by the commitment to terrible security practices' — systems described as 'solid as a paper Whopper wrapper in the rain,’ other RBI brands like Tim Hortons and Popeyes also vulnerable


Fast food firm quickly fixed vulnerabilities of whopping proportions, but didn't acknowledge the white-hat hackers.

While RBI may not be a very familiar name, this lax security means that systems powering mega brands like Burger King, Tim Hortons, and Popeyes, with over 30,000 locations worldwide, and all were almost trivially easy to hack. (Image credit: BobDaHacker and BobTheShoplifter)The vulnerabilities found were a big deal, as we will detail below, including allowing the duo to access employee accounts, ordering systems, and listen to recorded drive-thru conversations, among other exploits. (Image credit: BobDaHacker and BobTheShoplifter)Adding another teetering cherry to this deliciously vulnerable cake, the ethical hackers discovered they could access the full raw audio files of people ordering food at the outlet drive-throughs.

Get the Android app

Or read this on r/technology

Read more on:

Photo of systems

systems

Photo of commitment

commitment

Photo of rain

rain

Related news:

News photo

We hacked Burger King: How auth bypass led to drive-thru audio surveillance

News photo

Attackers snooping around Sitecore, dropping malware via public sample keys

News photo

Nx NPM packages poisoned in AI-assisted supply chain attack - Stolen dev credentials posted to GitHub as attackers abuse CLI tools for recon