A security flaw in the artificial intelligence chatbot McDonald's used to screen job applicants exposed the personal information of tens of millions of people, according to security researchers who documented the issue. The chatbot, built to handle initial hiring conversations, sat on a system that researchers were able to access after finding that an administrator account used the password 123456.

Once inside, the researchers reported that they could reach the personal records of a very large number of applicants who had interacted with the tool during the hiring process. The exposed data included the kind of contact and application details that job seekers routinely provide when applying for work. The researchers disclosed the vulnerability so it could be fixed rather than exploited.

The incident drew attention because of the simplicity of the failure. A widely known weak password guarded access to a system holding sensitive records, a basic security gap rather than a sophisticated attack. Security specialists noted that the case illustrates a broader pattern in which companies deploy AI tools quickly without applying standard access controls to the systems behind them.

McDonald's and the vendor that operated the chatbot addressed the flaw after it was reported. The episode added to a series of 2026 incidents in which AI-powered applications became the point of exposure for large volumes of user data. For companies adopting AI hiring and customer service tools, the case underscored that the security of the underlying platform matters as much as the capabilities of the AI itself.

Source: Tech.co - https://tech.co/news/data-breaches-updated-list