Skip to content

Domain Atlas / Hiring & employment screening AI

Case fileUnited States. McHire is a franchise-wide hiring platform operated for McDonald's and approximately 90 percent of its franchisees by Paradox.ai, a conversational-hiring vendor headquartered in Scottsdale, Arizona; the personality assessment inside the application flow is administered by a further third party, Traitify.com. The disclosure was made by US-based independent security researchers Ian Carroll and Sam Curry on 30 June 2025. No litigation, enforcement action or state attorney-general breach-notification filing tied to this incident was located as of 28 August 2026; the Maine attorney general's breach portal was offline at check time and the California attorney general's published list returned no entries, so that absence rests on searches plus partial registry checks rather than an exhaustive registry sweep. Paradox was acquired by Workday, Inc. under a definitive agreement announced 21 August 2025 and completed 1 October 2025.giant deployment

McHire and the 64-million-record custody exposure

Explore this deployment in the PAN Lab ↗

In the PAN Lab, the readouts of this case's model organization carry a shaded evidence band whose width follows the least-established class among the modeling inputs the readings rest on.

The least-established input behind this case's model organization's readings comes from a published baseline, not this deployment's own record. Evidence base: 14 published baseline.

McHire is the chatbot-first hiring front end for approximately 90 percent of McDonald's franchisees, powered by Paradox.ai's conversational assistant Olivia. An applicant supplies contact details and shift preferences in natural-language chat, answers screening questions, is routed into a personality assessment administered by a further third party, Traitify.com, presented as agree-or-disagree phrase items, and self-schedules an interview before advancing to a human review stage where franchisee owners and managers manage them through the hiring stages. The employment-decision surface here is pre-screening and flow control rather than final selection: the assistant screens and schedules, and a person decides. Paradox is a conversational-hiring vendor whose client list extends well beyond this brand to other high-volume frontline employers including Aramark, Lockheed Martin, Lowe's and Pepsi, and in acquisition coverage Wendy's, 7-Eleven and General Motors. No error rate, completion rate or complaint rate for the assistant has been published by anyone, and no independent evaluation of this deployment exists; what the record does contain is public complaints that the assistant was answering nonsensically, which is what prompted two outside researchers to examine the platform at all.[4]

What happened

Someone wants a job at a McDonald's. They go to McHire, the hiring front end used by roughly 90 percent of the brand's franchisees, and they talk to Olivia, a conversational assistant built by Paradox.ai. Olivia takes their name, email address, phone number, home address and shift preferences in ordinary chat. It asks the screening questions. It routes them into a personality assessment administered by a further company, Traitify, which puts short phrases in front of them to agree or disagree with — whether they enjoy overtime, that sort of thing. It books them an interview. Then it hands them to a human review stage, where a franchisee owner or manager takes over and works them through the hiring stages.

That flow is unremarkable, and on this record it worked. The assistant screens and schedules; it does not select. A person decides.

What makes this a hiring case rather than a security notice is what the conversation became. Every exchange and every field persisted into one vendor-held record. Each record held the applicant's name, email address, phone number, home address, shift preferences, the application's status and state-change history, the full raw transcript of what they typed to a recruiting agent, and an authentication token that would let whoever held it sign in to that applicant's own account. That is the employment-decision surface itself, in text, for everyone who ever applied.

In June 2025, Ian Carroll and Sam Curry went looking. What prompted them was not a security signal at all: it was a thread of public complaints on Reddit that Olivia was giving nonsensical answers. In what their own writeup describes as a cursory review, they found two things. The McHire administration login for restaurant owners accepted the default credentials 123456:123456 on a Paradox test-restaurant account, and entering them opened the administration panel for that instance, including its in-progress Olivia conversations. And a record-update endpoint, /api/lead/cem-xhr, performed no authorization check on its lead_id parameter: name an identifier, receive the matching applicant's unmasked record. Decrement the identifier, receive the next one.

Two numbers come out of that and they must be held apart, because the reporting does not always hold them apart. The researchers' own test application received a lead_id of about 64,185,742. Decrementing it returned other applicants' records. So records numbering to roughly 64 million were REACHABLE. That figure is the size of an identifier space; BleepingComputer states plainly that it represents the total number of job applications on McHire and not unique applicants. It is a derivation from an identifier, and it is not a count of anything taken. Separately, Paradox's public statement of 9 July 2025 says what was actually VIEWED: five candidate records containing personally identifiable information — names, emails, phones, IP addresses, all US-based candidates — plus two chat records containing no candidate information, viewed exclusively by the two researchers. It adds that the store held no Social Security numbers, that only the one client instance was affected, and that no candidate information was leaked online. That position is uncontradicted. It has also never been verified by any independent forensic report, and this file carries potential exposure and actual access as two different quantities at every point.

Then read the clock, and read it in both directions at once, because the same record contains both halves.

In one direction: the test-restaurant account had not been logged into since 2019 and, in Paradox's own published words, "frankly, should have been decommissioned." Six years. In those six years no employment regulator, no privacy regulator, no contractual security review, no audit and no internal review surfaced either flaw. McDonald's, which holds principal-to-vendor authority over a platform its franchisees run their hiring on, is not documented examining the custody surface at any point. The franchisees who actually use the platform had no visibility into Paradox's account or credential practice and, on this record, no channel through which to acquire any.

In the other direction: the disclosure email went out at 5:46 PM Eastern on 30 June 2025. McDonald's acknowledged it 38 minutes later. The default credentials were disabled by 7:31 PM the same evening, under two hours in. Paradox confirmed the insecure direct object reference (IDOR) fix at 10:18 PM on 1 July — about thirty hours from the email. On 9 July it published a "Responsible Security Update" that opened by accepting responsibility ("We take responsibility for this issue. Full stop.") and announced two things that had not existed before: a bug bounty programme and a dedicated security contact at security@paradox.ai.

The governance channel that actually fired, then, was the security-research responsible-disclosure norm — a professional convention with no legal force, operated by two people with no contract, no mandate, no statutory standing and no access. Detection and correction were both external to the deployment. This file moralises the speed in neither direction. The same record supports a six-year-dormant default credential and a thirty-hour external correction loop, and both are true.

McDonald's placed the failure with its supplier. Its statement, given to Wired and quoted verbatim by BleepingComputer and CSO Online, reads: "We're disappointed by this unacceptable vulnerability from a third-party provider, Paradox.ai. As soon as we learned of the issue, we mandated Paradox.ai to remediate the issue immediately, and it was resolved on the same day it was reported to us." That is the brand's characterisation of its own supplier and is carried as such.

Two weeks later a second thread appeared, and it is kept separate here. Krebs on Security reported that infostealer malware on Paradox developer machines in Vietnam — Nexus Stealer, plus a separate late-2024 compromise involving GitHub credentials — had exposed weak, reused seven-digit numeric passwords spanning multiple customer accounts, along with Okta single-sign-on and Atlassian tokens still valid into December 2025. Krebs also recorded that Paradox's client list runs well beyond this one brand: Aramark, Lockheed Martin, Lowe's, Pepsi, and in acquisition coverage Wendy's, 7-Eleven and General Motors. Paradox disputed the currency of the exposed passwords in part, attributing them to legacy password-manager migrations and saying few remained active. That reporting concerns the company's credential hygiene generally rather than this authorization chain, the dispute travels with it, and nothing in the Lab network derived from this case rests on it.

What did not happen is stated here as verified absence and never as exoneration. As of 28 August 2026 no lawsuit, no FTC, EEOC or state attorney-general enforcement action, and no state breach-notification filing tied to this incident could be located. The Maine attorney general's breach portal was offline at check time, reporting an apparent abuse of its reporting system, and the California attorney general's published list returned no entries, so the notification-registry finding rests on searches plus those partial checks. One search-engine summary asserted a Maine filing; no underlying record could be found and it is recorded here as unsubstantiated. Paradox's stated factual predicate — that only the two researchers viewed a handful of records and nothing was published — is the premise under which broad breach-notification duties would not attach. No independent adjudication of that premise exists.

Seven weeks after the disclosure, on 21 August 2025, Workday announced a definitive agreement to acquire Paradox; it completed the acquisition on 1 October 2025, folding Olivia into its talent-acquisition suite. Trade coverage of the deal carried the McHire incident and Paradox's scope dispute as context. Custody of the same records now sits inside a much larger human-capital software company, which is separately a subject in this atlas on an entirely different question. The two are not merged, and nothing about this deployment is derived from that one.

The sociotechnical reading

Most cases in this atlas are arguments about a decision: a score that was wrong, a rule that fired silently, an audit that measured the wrong thing. This one is not. The decision path here had the check it was supposed to have, and used it. The failure is one layer over, on the path that carried what the decision was made from.

Notice the asymmetry that produces, because it is the whole case. An applicant's path through Olivia is watched at every step by design: the assistant screens, a person reviews, a manager decides, and the stages are recorded. The same applicant's DATA travels a path nobody watched at all. Account lifecycle, credential policy and endpoint authorization all sat with the vendor, invisible to McDonald's, invisible to the franchisees running hiring on the platform, and invisible to the applicant, who was never in a position to see any of it. One path had three parties looking at it. The other had none, for six years.

Look at what actually detected the problem, because the ranking is instructive and unflattering. A national brand's contract authority detected nothing. A franchise network of owner-operators detected nothing — and could not have, because nothing in the interface they use would show them an account or an endpoint. No regulator of employment, privacy or consumer protection appears anywhere in the record, before or after. What detected it was two people with no standing, following a professional norm, prompted by complaints about something else entirely. What they found took a cursory review to find. The controls beneath were not sophisticated failures of a hard problem; they were a default password and a missing authorization check.

Then look at what happened once the finding existed, because the speed is genuinely remarkable and cuts against an easy reading. Thirty hours, end to end, including an acknowledgment in 38 minutes and a credential revoked in under two. Plus durable structure afterwards: a bug bounty and a security contact. The correction capability was excellent. The detection capability was absent. Those are different organizational properties and this deployment had one of them.

The vendor layer is doing something specific here that a single-employer case cannot show. One conversational-hiring platform holds candidate stores for many high-volume frontline employers, so one company's credential practice is the practice governing tens of millions of people's job applications across brands that have no relationship with each other and no view into it. A franchisee cannot audit it. A brand can mandate remediation after the fact, and this one did, inside the hour. Neither can see it in advance. Three months later the whole store moved inside a larger vendor stack, which changes who holds it and changes nothing about who can see it.

Finally, hold the two numbers apart one more time, because the gap between them is itself a governance object. Sixty-four million is what was reachable. Seven is what the holder of the data says was viewed. There is no third quantity — no independent forensic report — and no mechanism in this arrangement that would produce one. A reader is left with an attestation from the party that holds the logs and a derivation from two outsiders who happened to look. That is not an accusation against the attestation, which is uncontradicted. It is an observation about what an arrangement can and cannot make knowable, and it is the reason the Lab network drawn from this case runs its reconciliation pathway at zero.

The concepts used in this reading are defined in the Field Guide; the governance responses live in the Practice Library. The model organization for this case can be stress-tested in the PAN Lab.

Grounding sources for this case

The same sources that ground this model organization in the PAN library: evaluations, government documents, investigative reporting, and advocacy documentation, each labeled by tier.

carroll2025GroundingInvestigativeSave

Carroll, I., with Curry, S. (2025, July 9). Would you like an IDOR with that? Leaking 64 million McDonald's job applications (researcher disclosure writeup) https://ian.sh/mcdonalds

https://ian.sh/mcdonalds

Grounds: model org: mchire_paradox_chatbot

greenberg2025GroundingInvestigativeSave

Greenberg, A. (2025, July 9). McDonald's AI Hiring Bot Exposed Millions of Applicants' Data to Hackers Who Tried the Password '123456', Wired; publisher unfetchable from the verifying environment on 2026-08-28 and the article was not read https://www.wired.com/story/mcdonalds-ai-hiring-chat-bot-paradoxai/

https://www.wired.com/story/mcdonalds-ai-hiring-chat-bot-paradoxai/

Grounds: model org: mchire_paradox_chatbot

Seeing your organization in this case file?

The histories here are documented after the harm. Mapping a live deployment's pathways and pressures, before the incident report, is engagement work: intake, diagnosis, prescription, and monitoring, with every limitation stated.

Sources & Evidence

Claims made on this page and what supports them. The full registry lives in Evidence.

EmpiricalMcHire is the chatbot-first hiring front end for approximately 90 percent of McDonald's franchisees, powered b…

McHire is the chatbot-first hiring front end for approximately 90 percent of McDonald's franchisees, powered by Paradox.ai's conversational assistant Olivia. An applicant supplies contact details and shift preferences in natural-language chat, answers screening questions, is routed into a personality assessment administered by a further third party, Traitify.com, presented as agree-or-disagree phrase items, and self-schedules an interview before advancing to a human review stage where franchisee owners and managers manage them through the hiring stages. The employment-decision surface here is pre-screening and flow control rather than final selection: the assistant screens and schedules, and a person decides. Paradox is a conversational-hiring vendor whose client list extends well beyond this brand to other high-volume frontline employers including Aramark, Lockheed Martin, Lowe's and Pepsi, and in acquisition coverage Wendy's, 7-Eleven and General Motors. No error rate, completion rate or complaint rate for the assistant has been published by anyone, and no independent evaluation of this deployment exists; what the record does contain is public complaints that the assistant was answering nonsensically, which is what prompted two outside researchers to examine the platform at all.

carroll2025GroundingInvestigativeSave

Carroll, I., with Curry, S. (2025, July 9). Would you like an IDOR with that? Leaking 64 million McDonald's job applications (researcher disclosure writeup) https://ian.sh/mcdonalds

https://ian.sh/mcdonalds

Grounds: model org: mchire_paradox_chatbot

EmpiricalEvery conversation and every form field on McHire persisted into a single vendor-held lead record. Each record…

Every conversation and every form field on McHire persisted into a single vendor-held lead record. Each record contained the applicant's name, email address, phone number, home address, shift preferences, the application's status and state-change history, the full raw chat transcript of the exchange with the assistant, and an authentication token permitting login to that applicant's own consumer interface — an impersonation surface stored alongside the record it identifies. Records accumulated without any purge described in the record: identifiers could be walked backward across the platform's history. The researchers' own test application received a lead_id of approximately 64,185,742, so application records numbering to roughly 64 million were REACHABLE through the flawed endpoint. That figure is the size of an identifier space and BleepingComputer states it represents the total number of job applications on the platform rather than unique applicants; it is a derivation from an identifier and is not a count of records exfiltrated or of people harmed. What makes this store a hiring object rather than a generic personal-data store is its content: who applied where, what they told a recruiting agent in their own words, the assessment step they were routed through, and their application status history. No documented model-retraining loop reads from these records.

carroll2025GroundingInvestigativeSave

Carroll, I., with Curry, S. (2025, July 9). Would you like an IDOR with that? Leaking 64 million McDonald's job applications (researcher disclosure writeup) https://ian.sh/mcdonalds

https://ian.sh/mcdonalds

Grounds: model org: mchire_paradox_chatbot

EmpiricalSecurity researchers Ian Carroll and Sam Curry found two flaws in what their writeup describes as a cursory re…

Security researchers Ian Carroll and Sam Curry found two flaws in what their writeup describes as a cursory review, prompted by public complaints that the assistant was answering nonsensically. First, the McHire administration login for restaurant owners accepted the default credentials 123456:123456 on a Paradox test-restaurant account, granting administration-panel access for that instance including all in-progress conversations. Paradox states that this legacy test account had not been logged into since 2019 and, in its own words, should have been decommissioned. Second, the endpoint PUT /api/lead/cem-xhr performed no authorization check on its lead_id parameter, returning any applicant's unmasked record to a caller who simply named the identifier; decrementing the identifier returned other applicants' records. Before 30 June 2025 nothing in the record surfaced either flaw: no employment regulator, no privacy regulator, no contractual security review, no audit and no internal review is documented examining the custody surface, McDonald's is not documented exercising its principal-to-vendor authority over the platform before the disclosure email arrived, and franchisees running hiring on the platform had no visibility into vendor credential practice and no documented channel through which to acquire any.

carroll2025GroundingInvestigativeSave

Carroll, I., with Curry, S. (2025, July 9). Would you like an IDOR with that? Leaking 64 million McDonald's job applications (researcher disclosure writeup) https://ian.sh/mcdonalds

https://ian.sh/mcdonalds

Grounds: model org: mchire_paradox_chatbot

EmpiricalThe disclosure-to-remediation sequence is documented to the minute. The researchers emailed Paradox.ai and McD…

The disclosure-to-remediation sequence is documented to the minute. The researchers emailed Paradox.ai and McDonald's at 5:46 PM Eastern on 30 June 2025; McDonald's acknowledged at 6:24 PM, 38 minutes later; the default 123456 credentials were disabled by 7:31 PM the same evening, under two hours after the report; and Paradox confirmed the insecure direct object reference (IDOR) fix at 10:18 PM Eastern on 1 July 2025, approximately 29 to 30 hours after disclosure. On 9 July 2025 Paradox published a Responsible Security Update accepting responsibility in terms ('We take responsibility for this issue. Full stop.'), stating that five candidate records containing personally identifiable information — names, emails, phone numbers and IP addresses, all US-based candidates — plus two chat records containing no candidate information had been viewed and exclusively by the two researchers, that the store contained no Social Security numbers, that only the one client instance was affected and that no candidate information was leaked online, and announcing a bug bounty programme and a dedicated security contact at security@paradox.ai. That vendor position is uncontradicted and has never been verified by any independent forensic report, so potential exposure and actual access remain two separate quantities with nothing reconciling them. McDonald's statement, given to Wired and quoted verbatim in trade coverage, placed the failure with its supplier: 'We're disappointed by this unacceptable vulnerability from a third-party provider, Paradox.ai. As soon as we learned of the issue, we mandated Paradox.ai to remediate the issue immediately, and it was resolved on the same day it was reported to us.' The governance channel that fired was the security-research responsible-disclosure norm, operated by two people holding no contract, no mandate, no statutory standing and no access; detection and correction were both external to the deployment.

carroll2025GroundingInvestigativeSave

Carroll, I., with Curry, S. (2025, July 9). Would you like an IDOR with that? Leaking 64 million McDonald's job applications (researcher disclosure writeup) https://ian.sh/mcdonalds

https://ian.sh/mcdonalds

Grounds: model org: mchire_paradox_chatbot

EmpiricalNo litigation, enforcement action or state attorney-general breach-notification filing tied to the McHire expo…

No litigation, enforcement action or state attorney-general breach-notification filing tied to the McHire exposure was located as of 28 August 2026. That is stated as verified absence and never as exoneration, and the limits of the check are stated with it: the Maine attorney general's breach portal was offline at check time, reporting an apparent abuse of its data-breach reporting system, and the California attorney general's published breach list returned no entries, so the notification-registry finding rests on searches plus those partial registry checks rather than an exhaustive sweep. One search-engine summary asserted a Maine attorney-general filing; no underlying record could be found and it is recorded as unsubstantiated. Paradox's position — that only the two researchers viewed a handful of records and that nothing was leaked online — is the stated factual predicate under which broad breach-notification duties would not attach, and no independent adjudication of that position exists. A separate thread is kept separate: two weeks after the disclosure, Krebs on Security reported that infostealer malware on Paradox administrator and developer machines in Vietnam, identified as Nexus Stealer, had exposed weak seven-digit numeric passwords reused across multiple customer accounts along with Okta single-sign-on and Atlassian tokens valid into December 2025, and that a second developer compromise in late 2024 involved GitHub credentials. Paradox disputed the currency of the exposed passwords in part, attributing them to legacy password-manager migrations and stating that few remained active. That reporting concerns the company's credential hygiene generally rather than the McHire authorization chain specifically, and the dispute travels with it.

EmpiricalWorkday, Inc. announced a definitive agreement to acquire Paradox.ai on 21 August 2025, seven weeks after the …

Workday, Inc. announced a definitive agreement to acquire Paradox.ai on 21 August 2025, seven weeks after the disclosure, and completed the acquisition on 1 October 2025, folding the Olivia assistant into its talent-acquisition suite. Workday's own completion release describes the assistant as a conversational candidate-experience agent handling applications, screening support, self-scheduling and round-the-clock chat for frontline high-volume roles, and discloses no price. Trade coverage of the transaction carried the McHire incident and Paradox's dispute of its scope as due-diligence context, and recorded Paradox clients including Wendy's, 7-Eleven and General Motors. The effect on this case is that custody of the same applicant records moved inside a much larger human-capital software company three months after the exposure was disclosed. That acquirer is separately the subject of a different deployment record in this atlas on an unrelated question, and the two are not merged: this case is documented from the June and July 2025 record, when Paradox was independent.