Almost anyone who applied to work at McDonald’s earlier this year may have exposed their name, phone number, email address, physical address, and other personal information. Security researchers effortlessly broke into the administrative system overseeing applicants’ interactions with the generative AI chatbot that conducts most job interviews.
Security researcher Ian Carroll successfully logged into an administrative account for Paradox.ai, the company that built McDonald’s AI job interviewer, using ”123456” as both a username and password. Examining the internal site’s code quickly granted access to raw text from every chat it ever conducted.
Källa: McDonald’s AI hiring chatbot exposed data of 64 million applicants with ”123456” password