Domain Atlas / Hiring & employment screening AI
McHire and the 64-million-record custody exposure
Explore this deployment in the PAN Lab ↗
In the PAN Lab, the readouts of this case's model organization carry a shaded evidence band whose width follows the least-established class among the modeling inputs the readings rest on.
The least-established input behind this case's model organization's readings comes from a published baseline, not this deployment's own record. Evidence base: 14 published baseline.
McHire is the chatbot-first hiring front end for approximately 90 percent of McDonald's franchisees, powered by Paradox.ai's conversational assistant Olivia. An applicant supplies contact details and shift preferences in natural-language chat, answers screening questions, is routed into a personality assessment administered by a further third party, Traitify.com, presented as agree-or-disagree phrase items, and self-schedules an interview before advancing to a human review stage where franchisee owners and managers manage them through the hiring stages. The employment-decision surface here is pre-screening and flow control rather than final selection: the assistant screens and schedules, and a person decides. Paradox is a conversational-hiring vendor whose client list extends well beyond this brand to other high-volume frontline employers including Aramark, Lockheed Martin, Lowe's and Pepsi, and in acquisition coverage Wendy's, 7-Eleven and General Motors. No error rate, completion rate or complaint rate for the assistant has been published by anyone, and no independent evaluation of this deployment exists; what the record does contain is public complaints that the assistant was answering nonsensically, which is what prompted two outside researchers to examine the platform at all.[4]
What happened
Someone wants a job at a McDonald's. They go to McHire, the hiring front end used by roughly 90 percent of the brand's franchisees, and they talk to Olivia, a conversational assistant built by Paradox.ai. Olivia takes their name, email address, phone number, home address and shift preferences in ordinary chat. It asks the screening questions. It routes them into a personality assessment administered by a further company, Traitify, which puts short phrases in front of them to agree or disagree with — whether they enjoy overtime, that sort of thing. It books them an interview. Then it hands them to a human review stage, where a franchisee owner or manager takes over and works them through the hiring stages.
That flow is unremarkable, and on this record it worked. The assistant screens and schedules; it does not select. A person decides.
What makes this a hiring case rather than a security notice is what the conversation became. Every exchange and every field persisted into one vendor-held record. Each record held the applicant's name, email address, phone number, home address, shift preferences, the application's status and state-change history, the full raw transcript of what they typed to a recruiting agent, and an authentication token that would let whoever held it sign in to that applicant's own account. That is the employment-decision surface itself, in text, for everyone who ever applied.
In June 2025, Ian Carroll and Sam Curry went looking. What prompted them was not a security signal at all: it was a thread of public complaints on Reddit that Olivia was giving nonsensical answers. In what their own writeup describes as a cursory review, they found two things. The McHire administration login for restaurant owners accepted the default credentials 123456:123456 on a Paradox test-restaurant account, and entering them opened the administration panel for that instance, including its in-progress Olivia conversations. And a record-update endpoint, /api/lead/cem-xhr, performed no authorization check on its lead_id parameter: name an identifier, receive the matching applicant's unmasked record. Decrement the identifier, receive the next one.
Two numbers come out of that and they must be held apart, because the reporting does not always hold them apart. The researchers' own test application received a lead_id of about 64,185,742. Decrementing it returned other applicants' records. So records numbering to roughly 64 million were REACHABLE. That figure is the size of an identifier space; BleepingComputer states plainly that it represents the total number of job applications on McHire and not unique applicants. It is a derivation from an identifier, and it is not a count of anything taken. Separately, Paradox's public statement of 9 July 2025 says what was actually VIEWED: five candidate records containing personally identifiable information — names, emails, phones, IP addresses, all US-based candidates — plus two chat records containing no candidate information, viewed exclusively by the two researchers. It adds that the store held no Social Security numbers, that only the one client instance was affected, and that no candidate information was leaked online. That position is uncontradicted. It has also never been verified by any independent forensic report, and this file carries potential exposure and actual access as two different quantities at every point.
Then read the clock, and read it in both directions at once, because the same record contains both halves.
In one direction: the test-restaurant account had not been logged into since 2019 and, in Paradox's own published words, "frankly, should have been decommissioned." Six years. In those six years no employment regulator, no privacy regulator, no contractual security review, no audit and no internal review surfaced either flaw. McDonald's, which holds principal-to-vendor authority over a platform its franchisees run their hiring on, is not documented examining the custody surface at any point. The franchisees who actually use the platform had no visibility into Paradox's account or credential practice and, on this record, no channel through which to acquire any.
In the other direction: the disclosure email went out at 5:46 PM Eastern on 30 June 2025. McDonald's acknowledged it 38 minutes later. The default credentials were disabled by 7:31 PM the same evening, under two hours in. Paradox confirmed the insecure direct object reference (IDOR) fix at 10:18 PM on 1 July — about thirty hours from the email. On 9 July it published a "Responsible Security Update" that opened by accepting responsibility ("We take responsibility for this issue. Full stop.") and announced two things that had not existed before: a bug bounty programme and a dedicated security contact at security@paradox.ai.
The governance channel that actually fired, then, was the security-research responsible-disclosure norm — a professional convention with no legal force, operated by two people with no contract, no mandate, no statutory standing and no access. Detection and correction were both external to the deployment. This file moralises the speed in neither direction. The same record supports a six-year-dormant default credential and a thirty-hour external correction loop, and both are true.
McDonald's placed the failure with its supplier. Its statement, given to Wired and quoted verbatim by BleepingComputer and CSO Online, reads: "We're disappointed by this unacceptable vulnerability from a third-party provider, Paradox.ai. As soon as we learned of the issue, we mandated Paradox.ai to remediate the issue immediately, and it was resolved on the same day it was reported to us." That is the brand's characterisation of its own supplier and is carried as such.
Two weeks later a second thread appeared, and it is kept separate here. Krebs on Security reported that infostealer malware on Paradox developer machines in Vietnam — Nexus Stealer, plus a separate late-2024 compromise involving GitHub credentials — had exposed weak, reused seven-digit numeric passwords spanning multiple customer accounts, along with Okta single-sign-on and Atlassian tokens still valid into December 2025. Krebs also recorded that Paradox's client list runs well beyond this one brand: Aramark, Lockheed Martin, Lowe's, Pepsi, and in acquisition coverage Wendy's, 7-Eleven and General Motors. Paradox disputed the currency of the exposed passwords in part, attributing them to legacy password-manager migrations and saying few remained active. That reporting concerns the company's credential hygiene generally rather than this authorization chain, the dispute travels with it, and nothing in the Lab network derived from this case rests on it.
What did not happen is stated here as verified absence and never as exoneration. As of 28 August 2026 no lawsuit, no FTC, EEOC or state attorney-general enforcement action, and no state breach-notification filing tied to this incident could be located. The Maine attorney general's breach portal was offline at check time, reporting an apparent abuse of its reporting system, and the California attorney general's published list returned no entries, so the notification-registry finding rests on searches plus those partial checks. One search-engine summary asserted a Maine filing; no underlying record could be found and it is recorded here as unsubstantiated. Paradox's stated factual predicate — that only the two researchers viewed a handful of records and nothing was published — is the premise under which broad breach-notification duties would not attach. No independent adjudication of that premise exists.
Seven weeks after the disclosure, on 21 August 2025, Workday announced a definitive agreement to acquire Paradox; it completed the acquisition on 1 October 2025, folding Olivia into its talent-acquisition suite. Trade coverage of the deal carried the McHire incident and Paradox's scope dispute as context. Custody of the same records now sits inside a much larger human-capital software company, which is separately a subject in this atlas on an entirely different question. The two are not merged, and nothing about this deployment is derived from that one.
The sociotechnical reading
Most cases in this atlas are arguments about a decision: a score that was wrong, a rule that fired silently, an audit that measured the wrong thing. This one is not. The decision path here had the check it was supposed to have, and used it. The failure is one layer over, on the path that carried what the decision was made from.
Notice the asymmetry that produces, because it is the whole case. An applicant's path through Olivia is watched at every step by design: the assistant screens, a person reviews, a manager decides, and the stages are recorded. The same applicant's DATA travels a path nobody watched at all. Account lifecycle, credential policy and endpoint authorization all sat with the vendor, invisible to McDonald's, invisible to the franchisees running hiring on the platform, and invisible to the applicant, who was never in a position to see any of it. One path had three parties looking at it. The other had none, for six years.
Look at what actually detected the problem, because the ranking is instructive and unflattering. A national brand's contract authority detected nothing. A franchise network of owner-operators detected nothing — and could not have, because nothing in the interface they use would show them an account or an endpoint. No regulator of employment, privacy or consumer protection appears anywhere in the record, before or after. What detected it was two people with no standing, following a professional norm, prompted by complaints about something else entirely. What they found took a cursory review to find. The controls beneath were not sophisticated failures of a hard problem; they were a default password and a missing authorization check.
Then look at what happened once the finding existed, because the speed is genuinely remarkable and cuts against an easy reading. Thirty hours, end to end, including an acknowledgment in 38 minutes and a credential revoked in under two. Plus durable structure afterwards: a bug bounty and a security contact. The correction capability was excellent. The detection capability was absent. Those are different organizational properties and this deployment had one of them.
The vendor layer is doing something specific here that a single-employer case cannot show. One conversational-hiring platform holds candidate stores for many high-volume frontline employers, so one company's credential practice is the practice governing tens of millions of people's job applications across brands that have no relationship with each other and no view into it. A franchisee cannot audit it. A brand can mandate remediation after the fact, and this one did, inside the hour. Neither can see it in advance. Three months later the whole store moved inside a larger vendor stack, which changes who holds it and changes nothing about who can see it.
Finally, hold the two numbers apart one more time, because the gap between them is itself a governance object. Sixty-four million is what was reachable. Seven is what the holder of the data says was viewed. There is no third quantity — no independent forensic report — and no mechanism in this arrangement that would produce one. A reader is left with an attestation from the party that holds the logs and a derivation from two outsiders who happened to look. That is not an accusation against the attestation, which is uncontradicted. It is an observation about what an arrangement can and cannot make knowable, and it is the reason the Lab network drawn from this case runs its reconciliation pathway at zero.
The concepts used in this reading are defined in the Field Guide; the governance responses live in the Practice Library. The model organization for this case can be stress-tested in the PAN Lab.