Get the latest tech news

McDonald's AI hiring chatbot exposed data of 64 million applicants with "123456" password


Security researcher Ian Carroll successfully logged into an administrative account for Paradox.ai, the company that built McDonald's AI job interviewer, using "123456" as both a username and...

Security researchers effortlessly broke into the administrative system overseeing applicants' interactions with the generative AI chatbot that conducts most job interviews. Security researcher Ian Carroll successfully logged into an administrative account for Paradox.ai, the company that built McDonald's AI job interviewer, using "123456" as both a username and password. Although McDonald's hiring website attempts to push users toward a single sign-on, Carroll noticed a link in small text that led to a separate Paradox employee login page.

Get the Android app

Or read this on r/technology

Read more on:

Photo of McDonald

McDonald

Photo of Password

Password

Photo of applicants

applicants

Related news:

News photo

McDonald's AI Hiring Bot Exposed Millions of Applicants' Data To Hackers

News photo

McDonald’s AI Hiring Bot Exposed Millions of Applicants' Data to Hackers Using the Password ‘123456’

News photo

Sitecore CMS exploit chain starts with hardcoded 'b' password