PAN Lab example
McHire, McDonald's franchise hiring platform
Everything the applicant typed, and who could ask for it
A person applies for a job at a restaurant and talks to a chatbot. It takes their name, email address, phone number, home address and shift preferences in ordinary conversation, asks the screening questions, hands them to a trait assessment run by a further company, books an interview, and passes them to a human review stage where a franchisee manager takes over. That is the whole hiring flow, and on this record it worked. Modeled on the documented record of the McHire platform and the Paradox.ai assistant Olivia, the chatbot-first hiring front end for approximately ninety percent of McDonald's franchisees. What makes this a hiring case rather than a security notice is what the conversation became. Every exchange and every field persisted into one vendor-held record: the contact details, the shift preferences, the application's status history, the full raw transcript of what the applicant typed to a recruiting agent, and an authentication token that would let its holder sign in as that applicant. That is the employment-decision surface itself, in text, for everyone who ever applied. Two outside researchers went looking in June 2025, after seeing public complaints that the chatbot was answering nonsensically. In a cursory review they found two things. The administration login for restaurant owners accepted a default six-digit credential on a Paradox test-restaurant account. And one record endpoint took an identifier and returned the matching applicant's unmasked record, performing no authorization check on who was asking. Hold the next two numbers apart, because the reporting does not always. The researchers' own test application received an identifier of about 64,185,742, so records numbering to roughly sixty-four million were REACHABLE — the size of an identifier space, counted in applications rather than in distinct people. Paradox states that five candidate records containing personal information plus two chat records containing none were actually VIEWED, only by the two researchers, that the store held no social security numbers, that a single client instance was affected and that nothing was leaked online. That statement is uncontradicted and no independent forensic report stands behind it. Then read the clock, and read it in both directions at once. The test account had not been logged into since 2019 and, in Paradox's own words, should have been decommissioned: six years, with no employment regulator, privacy regulator, contract audit or internal review surfacing either flaw. One disclosure email at 5:46 PM Eastern on 30 June 2025 produced acknowledgment from McDonald's in 38 minutes, the credential disabled by 7:31 PM, and a confirmed authorization fix at 10:18 PM the next day, about thirty hours in. On 9 July Paradox published a statement accepting responsibility and launched a bug bounty and a dedicated security contact. The governance channel that actually fired was a professional norm with no legal force, operating entirely outside the deployment. This file moralises the speed in neither direction, because the same record holds both halves. What did not happen is stated as verified absence and never as exoneration: no lawsuit, no enforcement action and no state breach-notification filing tied to this incident was located as of 28 August 2026, and one state registry was offline while another showed no published entries at check time, so that absence rests on searches plus partial registry checks. A separate thread runs beside this one and stays separate: two weeks later an independent security journalist reported infostealer compromises of Paradox developer machines exposing weak reused numeric passwords and still-valid single-sign-on and issue-tracker tokens, which Paradox partly disputed as legacy password-manager migrations. That concerns the company's credential hygiene generally, not this authorization chain. Seven weeks after the disclosure, Workday agreed to acquire Paradox, completing on 1 October 2025 and relocating custody of the same records inside a larger vendor stack. Before you pick a target level: this board cannot be won under Service and Safety Targets or All Governance Targets, because two pathways stay open at every price. Take every instrument the parties in this record could actually reach and ignore the budget entirely. The best any combination of them reaches is those same two, at a cost of ten against the seven you are given. They are the applicant arriving at the person who decides, and the trait assessment's result arriving with them. Those two are not a gap in this deployment's governance. They are the human review stage — the one part of this arrangement that did its job, drawn as what it is: a machine's output reaching a person. Closing them would not be a better-governed version of this deployment. It would be the removal of its only working check. That is a measurement of the deployment this network is drawn from, not a puzzle waiting to be cracked. Explore and Service Targets Only can both be won, and cheaply: one instrument, costing three of your seven, and it is the one this record shows actually pulled.
Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.
What this models
This example runs on the Custody-class conversational hiring intake network: 11 components and 25 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.
Evidence base: 14 published baseline. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.
- baseline
Two quantities in this record are close enough in the reporting to be read as one, and this network keeps them apart at every point. Records numbering to roughly 64 million were REACHABLE through the record endpoint: the researchers' own test application received an identifier of about 64,185,742, and decrementing it returned other applicants' records. That figure is the size of an identifier space, it counts applications rather than distinct people, and it is a derivation rather than a measurement of anything taken. Separately, the vendor states that five candidate records containing personal information plus two chat records containing none were actually viewed, only by the two researchers, that the store held no social security numbers, that a single client instance was affected and that nothing was leaked online. That statement is uncontradicted and has never been independently verified by any forensic report. The egress pathway is therefore drawn at the low rung, on what the record shows retrieved, and the identifier space is written into the store's description as reach rather than into any pathway's width.
- baseline
Demand is drawn at the top of the range and capacity in the middle, and the pair is derived rather than defaulted. Demand: the platform is the chatbot-first hiring front end for approximately ninety percent of one national restaurant brand's franchisees, its identifier space had reached the order of sixty-four million applications, and the same vendor's client list runs to other high-volume frontline employers. Capacity is the counterfactual floor — what the human process delivers with no AI at all — and it sits at the spec's competent-human-baseline value for a specific reason: the human review stage in this deployment is documented, downstream and running, with franchisee staff working applicants through the hiring stages, so the manual comparator is neither hypothetical nor absent; but no source in this record measures the pre-platform intake process, and this deployment has no reported time-to-hire, throughput, cost or quality figure of any kind from anyone. A higher value would assert a strong manual comparator that no source documents.
- baseline
The PAN entry for this deployment carries the applicant's live conversation and the stored applicant record as ONE object: its widest edge reads from the record store into the agent and its source line says the record and the dialogue are the same object here. This network splits them, drawing what the applicant types as an external input feed and what it becomes as a record store, and it draws that one PAN edge on the input arm only — no second read from the store into the agent is drawn, because that would count one documented read twice. The split is the case: the distance between an intake act that worked as designed and a record it filled that nobody with a mandate examined for six years is the whole subject, and a diagram that merges them cannot show it.
- baseline
No pathway runs from the applicant record back into the conversational agent, and that absence is derived rather than overlooked. The dossier's account of what this record does is explicit: the store is the hazard rather than a contamination loop, records accumulate monotonically, and no model-retraining loop from these records is documented anywhere. This is the structural difference between this deployment and every hiring board built on a screen trained on past decisions: the danger here is not that the store teaches the system to repeat a past pattern, it is that the store exists, keeps everything and was reachable. The one read the store does feed is the trait assessment reading the applicant's own live session, which is drawn at the low rung on the same evidence.
- baseline
Seven of this network's twenty-five pathways are marked as carrying identifiable applicant data, and they are exactly the ones whose payload is an applicant's own words, contact details, session or record. The one pathway that leaves the governed system is marked with them: a record endpoint that took an identifier and returned the matching applicant's unmasked record, including an authentication token for that applicant's own account. The scenario's privacy posture is derived from that set and from the retention the record describes, never from any adjudicated finding, because there is none.
- baseline
The boundary node is named and never measured, which is the schema's own rule for it and the honest posture for this record. Nothing downstream of the retrieval is computed here, because nothing downstream of it was ever established: no misuse, no secondary distribution and no harm to any applicant is documented by anyone, and the vendor states nothing was leaked online. Drawing the boundary lets the way data crossed it be seen and closed; it does not assert a consequence on the other side.
- baseline
The two reviewing channels learn what they learn in different ways, which is the point of drawing two. The outside research channel carries a documented inbound read of the platform's access and authorization surface, and that read is how both flaws were found. The brand's contract authority carries no read of its own: what reaches it is the disclosure itself, arriving from the outside channel, which is the whole of its documented detection capability and is why the pathway that brings it is drawn as the arrival rather than as a second read of the same email. Neither channel reads the applicant record itself, and the record consulted describes no party that both holds a mandate over this deployment and reads what the store contains.
- baseline
This network carries four sideways channels between operator classes and every one of them is drawn as a check rather than as a channel that spreads failure. That is derived from the record rather than chosen: the sideways traffic this deployment documents is a disclosure email, a second copy of that email, a principal's mandate to remediate, and a franchisee's report of a concern. No source describes practice, shortcut or belief travelling between these classes in a way that carries error with it, and drawing one would invent a mechanism the record does not contain.
- baseline
The embedded trait assessment is drawn as its own component because a further company administering a step inside the vendor's flow is a structural fact about this application, not a detail: one job application crosses three organizations. What is drawn around it is deliberately thin. Its read of the session and its write to the record are both at the low rung, and the read of the component by anything other than itself is at zero, because no source consulted describes its scoring, its weighting, any threshold, any validation, or any party checking it. The mid-conversation hand-off into it is carried by that read rather than by a second pathway of its own: PAN draws the step once, and what makes the chain legible is the component, which this diagram draws. The PAN entry reaches the same conclusion from the other side, giving this component the lowest correction value in its file for exactly that reason.
- baseline
The reconciliation of the public account against the access and log state it describes is drawn at zero, and the claim behind that zero is narrow. It does not say the vendor's account is wrong; the account is uncontradicted. It says no independent forensic report stands behind it in any source consulted, so a reader has an attestation from the party that holds the data and a derivation from two outside researchers, and nothing that reconciles the two. The store-to-store transfer that made the defects public runs at the middle rung in one direction while the check runs at zero in the other, between the same two stores.
- baseline
One pathway departs from the width mapping this network otherwise applies to every PAN edge without exception, and the departure is declared rather than quiet. The PAN entry draws the franchisee-to-vendor peer hop at its own floor, and its source line gives the reason: nothing in the record describes a channel by which a franchisee could raise, or even observe, a platform security concern, so the value carries an absence rather than an observed weakness. The mapping used here would put that width at the low rung; the derivation method says a check is drawn at zero where the source documents it absent, and this source does. PAN has no zero rung available to it. The Lab does, and using it is what makes the finding visible.
- baseline
A second thread runs beside this one in the public record and this network does not draw it. Two weeks after the disclosure, an independent security journalist reported infostealer compromises of vendor developer machines exposing weak reused numeric passwords across customer accounts, plus single-sign-on and issue-tracker tokens valid months out, and a separate earlier compromise involving source-control credentials; the vendor disputed the currency of those passwords, attributing them partly to legacy password-manager migrations. That reporting concerns the vendor's corporate credential hygiene generally rather than this authorization chain. It informs how the access record's condition is described, it travels with the vendor's dispute wherever it appears, and no pathway width, stressor or lever on this board rests on it.
- baseline
Applicants are not modelled. No hiring decision, advancement, rejection or employment outcome for any person is computed from anything drawn here, and no score over any person is authored anywhere in this bundle. The applicant counts that appear are recorded external observations: an identifier space derived by two researchers from their own test application, and a vendor's count of records it says were viewed. Applicants had no visibility into the retention of what they typed and no control over it, and that is stated here rather than drawn, because there is no node a pathway from them could attach to.
- baseline
The vendor was absorbed into a much larger human-capital software company three months after the disclosure, under an agreement announced 21 August 2025 and completed 1 October 2025, relocating custody of the same records inside a consolidating vendor stack. That acquirer is separately a shipped org in this catalogue on an entirely different question, and the two are not merged: this network is derived from the June and July 2025 record, when the vendor was independent, and nothing here imports that other deployment's evidence or dynamics. The acquisition is carried as aftermath in the case file and in one scenario limitation, and it moves no width, no stressor and no lever.
What this example does not show
- LITIGATION AND REGULATORY POSTURE, verbatim from the evidence dossier and load-bearing. Concluded as a security incident: vulnerabilities remediated within ~30 hours of disclosure; vendor launched a bug bounty and security contact; no litigation or regulator action identified as of Aug 2026; vendor subsequently acquired by Workday
- The two exposure figures are different quantities and this network never lets them merge. Roughly 64 million is a count of application RECORDS reachable through the record endpoint, derived by the researchers from their own test identifier of about 64,185,742. It is the size of an identifier space, it counts applications rather than unique applicants, and it is not a count of records exfiltrated. Paradox's position is that five candidate records containing personal information plus two chat records containing none were viewed, exclusively by the two researchers, that the store held no social security numbers, that only one client instance was affected and that nothing was leaked online. That position is uncontradicted and it is also unverified by any independent forensic report. Nothing on this diagram computes harm to any applicant, because no source establishes any.
- The regulatory and litigation silence is stated as VERIFIED ABSENCE and never as exoneration. No lawsuit, no FTC, EEOC or state attorney-general enforcement action, and no state breach-notification filing tied to this incident was located as of 28 August 2026. That absence rests on searches plus partial registry checks rather than an exhaustive sweep: one state's breach portal was offline at check time and another state's published list returned no entries. One search-engine summary asserting a state filing could not be substantiated against any underlying record and is treated as unsupported. Paradox's stated factual predicate — that only the two researchers viewed a handful of records and nothing was published — is the premise under which broad notification duties would not attach, and no independent adjudication of that premise exists.
- This is a security and data-protection record, not a bias record, and nothing here asserts otherwise. No adverse-action finding, no discrimination finding and no scoring-error evidence exists for this deployment. The hiring dimension is the SENSITIVITY of what the store held — applications, screening conversations, an assessment step and a status history, which together are the employment-decision surface — rather than a contested employment decision. No party has been found to have discriminated against anyone, because no such allegation appears in this record at all.
- The independent security reporting about the vendor's broader credential hygiene is a SEPARATE thread and is kept separate. Two weeks after the disclosure, a security journalist reported infostealer compromises of Paradox developer machines in Vietnam exposing weak seven-digit numeric passwords reused across multiple customer accounts, plus single-sign-on and issue-tracker tokens valid months out, and a second developer compromise in late 2024 involving source-control credentials. Paradox disputed the currency of the exposed passwords, attributing them partly to legacy password-manager migrations and saying few remained active. That reporting concerns the company generally and not the authorization chain described here, the dispute travels with it wherever it appears, and no pathway width, pressure or instrument on this board rests on it.
- Every statement about what was actually accessed, about the test account's dormancy, and about the absence of social security numbers is the VENDOR speaking about itself, and is marked as such wherever it is used. The brand's characterisation — that it was disappointed by an unacceptable vulnerability from a third-party provider and mandated immediate remediation as soon as it learned of the issue — is likewise the brand's own statement about its own supplier. The researchers' technical account and the independent trade and security reporting are the independent streams, and where the two registers disagree this file carries both rather than choosing.
- The original major-press account of this incident could not be fetched from the verifying environment and was not read. Its existence, its author and the brand's statement given to it are corroborated verbatim by two trade accounts that quote it, and every quoted phrase used anywhere in this bundle comes from those corroborating sources rather than from the unread article.
- The trait assessment inside the application flow is drawn thin because the evidence is thin, and the thinness is the finding rather than a gap in the modelling. The sources establish that a further company administers an agree-or-disagree trait assessment between shift-preference capture and the human review stage. They do not establish its scoring, its weighting, any threshold, any validation, or any party checking it. Trade coverage listed personality-test results among the exposed data categories; that is press characterisation, and the researchers' own itemisation covers contact data, shift preferences, status history, the raw transcript and an authentication token.
- The vendor's acquisition is carried as aftermath and the two deployments are never merged. Workday announced a definitive agreement to acquire Paradox on 21 August 2025, seven weeks after the disclosure, and completed it on 1 October 2025, folding the assistant into its talent-acquisition suite. Workday is separately a shipped org in this catalogue on an entirely different question, with its own evidence and its own dynamics, and nothing from that board appears here. This network is derived from the June and July 2025 record, when Paradox was independent. The press-reported purchase price rests on a page that returned an error to the verifying environment and the acquirer's own release discloses no price, so no figure appears anywhere in this bundle.
- Applicants are not modelled. No hiring decision, advancement, rejection or employment outcome for any person is computed from anything on this diagram, and no score over any person is authored anywhere. The applicant figures that appear are recorded external observations: an identifier space derived by two researchers, and a count of records the vendor says were viewed. The structural fact the record does establish about applicants — that they had no visibility into the retention of what they typed and no control over it — is stated rather than drawn, because there is no node on this diagram a pathway from them could attach to.
Sources and evidence
What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.
McHire is the chatbot-first hiring front end for approximately 90 percent of McDonald's franchisees, powered by Paradox.ai's conversational assistant Olivia. An applicant supplies contact details and shift preferences in natural-language chat, answers screening questions, is routed into a personality assessment administered by a further third party, Traitify.com, presented as agree-or-disagree phrase items, and self-schedules an interview before advancing to a human review stage where franchisee owners and managers manage them through the hiring stages. The employment-decision surface here is pre-screening and flow control rather than final selection: the assistant screens and schedules, and a person decides. Paradox is a conversational-hiring vendor whose client list extends well beyond this brand to other high-volume frontline employers including Aramark, Lockheed Martin, Lowe's, and Pepsi, and in acquisition coverage Wendy's, 7-Eleven, and General Motors. No error rate, completion rate, or complaint rate for the assistant has been published by anyone, and no independent evaluation of this deployment exists; what the record does contain is public complaints that the assistant was answering nonsensically, which is what prompted two outside researchers to examine the platform at all.
empirical- Investigative Carroll, I., with Curry, S. (2025, July 9). Would you like an IDOR with that? Leaking 64 million McDonald's job applications (researcher disclosure writeup) https://ian.sh/mcdonalds
- Trade press BleepingComputer (2025). '123456' password exposed chats for 64 million McDonald's job chatbot applications https://www.bleepingcomputer.com/news/security/123456-password-exposed-chats-for-64-million-mcdonalds-job-chatbot-applications/
- Investigative Krebs on Security (2025, July). Poor Passwords Tattle on AI Hiring Bot Maker Paradox.ai https://krebsonsecurity.com/2025/07/poor-passwords-tattle-on-ai-hiring-bot-maker-paradox-ai/
- Vendor Workday, Inc. (2025, October 1). Workday Completes Acquisition of Paradox (newsroom release) https://newsroom.workday.com/2025-10-01-Workday-Completes-Acquisition-of-Paradox
Every conversation and every form field on McHire persisted into a single vendor-held lead record. Each record contained the applicant's name, email address, phone number, home address, shift preferences, the application's status and state-change history, the full raw chat transcript of the exchange with the assistant, and an authentication token permitting login to that applicant's own consumer interface — an impersonation surface stored alongside the record it identifies. Records accumulated without any purge described in the record: identifiers could be walked backward across the platform's history. The researchers' own test application received a lead_id of approximately 64,185,742, so application records numbering to roughly 64 million were REACHABLE through the flawed endpoint. That figure is the size of an identifier space and BleepingComputer states it represents the total number of job applications on the platform rather than unique applicants; it is a derivation from an identifier and is not a count of records exfiltrated or of people harmed. What makes this store a hiring object rather than a generic personal-data store is its content: who applied where, what they told a recruiting agent in their own words, the assessment step they were routed through, and their application status history. No documented model-retraining loop reads from these records.
empirical- Investigative Carroll, I., with Curry, S. (2025, July 9). Would you like an IDOR with that? Leaking 64 million McDonald's job applications (researcher disclosure writeup) https://ian.sh/mcdonalds
- Trade press BleepingComputer (2025). '123456' password exposed chats for 64 million McDonald's job chatbot applications https://www.bleepingcomputer.com/news/security/123456-password-exposed-chats-for-64-million-mcdonalds-job-chatbot-applications/
- Trade press CSO Online (2025). McDonald's AI hiring tool's password '123456' exposed data of 64M applicants https://www.csoonline.com/article/4020919/mcdonalds-ai-hiring-tools-password-123456-exposes-data-of-64m-applicants.html
Security researchers Ian Carroll and Sam Curry found two flaws in what their writeup describes as a cursory review, prompted by public complaints that the assistant was answering nonsensically. First, the McHire administration login for restaurant owners accepted the default credentials 123456:123456 on a Paradox test-restaurant account, granting administration-panel access for that instance including all in-progress conversations. Paradox states that this legacy test account had not been logged into since 2019 and, in its own words, should have been decommissioned. Second, the endpoint PUT /api/lead/cem-xhr performed no authorization check on its lead_id parameter, returning any applicant's unmasked record to a caller who simply named the identifier; decrementing the identifier returned other applicants' records. Before 30 June 2025 nothing in the record surfaced either flaw: no employment regulator, no privacy regulator, no contractual security review, no audit, and no internal review is documented examining the custody surface, McDonald's is not documented exercising its principal-to-vendor authority over the platform before the disclosure email arrived, and franchisees running hiring on the platform had no visibility into vendor credential practice and no documented channel through which to acquire any.
empirical- Investigative Carroll, I., with Curry, S. (2025, July 9). Would you like an IDOR with that? Leaking 64 million McDonald's job applications (researcher disclosure writeup) https://ian.sh/mcdonalds
- Trade press CSO Online (2025). McDonald's AI hiring tool's password '123456' exposed data of 64M applicants https://www.csoonline.com/article/4020919/mcdonalds-ai-hiring-tools-password-123456-exposes-data-of-64m-applicants.html
- Vendor Paradox.ai (2025, July 9). Responsible Security Update https://www.paradox.ai/blog/responsible-security-update
The disclosure-to-remediation sequence is documented to the minute. The researchers emailed Paradox.ai and McDonald's at 5:46 PM Eastern on 30 June 2025; McDonald's acknowledged at 6:24 PM, 38 minutes later; the default 123456 credentials were disabled by 7:31 PM the same evening, under two hours after the report; and Paradox confirmed the insecure direct object reference (IDOR) fix at 10:18 PM Eastern on 1 July 2025, approximately 29 to 30 hours after disclosure. On 9 July 2025 Paradox published a Responsible Security Update accepting responsibility in terms ('We take responsibility for this issue. Full stop.'), stating that five candidate records containing personally identifiable information — names, emails, phone numbers, and IP addresses, all US-based candidates — plus two chat records containing no candidate information had been viewed and exclusively by the two researchers, that the store contained no Social Security numbers, that only the one client instance was affected, and that no candidate information was leaked online, and announcing a bug bounty programme and a dedicated security contact at security@paradox.ai. That vendor position is uncontradicted and has never been verified by any independent forensic report, so potential exposure and actual access remain two separate quantities with nothing reconciling them. McDonald's statement, given to Wired and quoted verbatim in trade coverage, placed the failure with its supplier: 'We're disappointed by this unacceptable vulnerability from a third-party provider, Paradox.ai. As soon as we learned of the issue, we mandated Paradox.ai to remediate the issue immediately, and it was resolved on the same day it was reported to us.' The governance channel that fired was the security-research responsible-disclosure norm, operated by two people holding no contract, no mandate, no statutory standing, and no access; detection and correction were both external to the deployment.
empirical- Investigative Carroll, I., with Curry, S. (2025, July 9). Would you like an IDOR with that? Leaking 64 million McDonald's job applications (researcher disclosure writeup) https://ian.sh/mcdonalds
- Vendor Paradox.ai (2025, July 9). Responsible Security Update https://www.paradox.ai/blog/responsible-security-update
- Trade press BleepingComputer (2025). '123456' password exposed chats for 64 million McDonald's job chatbot applications https://www.bleepingcomputer.com/news/security/123456-password-exposed-chats-for-64-million-mcdonalds-job-chatbot-applications/
- Trade press CSO Online (2025). McDonald's AI hiring tool's password '123456' exposed data of 64M applicants https://www.csoonline.com/article/4020919/mcdonalds-ai-hiring-tools-password-123456-exposes-data-of-64m-applicants.html
No litigation, enforcement action, or state attorney-general breach-notification filing tied to the McHire exposure was located as of 28 August 2026. That is stated as verified absence and never as exoneration, and the limits of the check are stated with it: the Maine attorney general's breach portal was offline at check time, reporting an apparent abuse of its data-breach reporting system, and the California attorney general's published breach list returned no entries, so the notification-registry finding rests on searches plus those partial registry checks rather than an exhaustive sweep. One search-engine summary asserted a Maine attorney-general filing; no underlying record could be found and it is recorded as unsubstantiated. Paradox's position — that only the two researchers viewed a handful of records and that nothing was leaked online — is the stated factual predicate under which broad breach-notification duties would not attach, and no independent adjudication of that position exists. A separate thread is kept separate: two weeks after the disclosure, Krebs on Security reported that infostealer malware on Paradox administrator and developer machines in Vietnam, identified as Nexus Stealer, had exposed weak seven-digit numeric passwords reused across multiple customer accounts along with Okta single-sign-on and Atlassian tokens valid into December 2025, and that a second developer compromise in late 2024 involved GitHub credentials. Paradox disputed the currency of the exposed passwords in part, attributing them to legacy password-manager migrations and stating that few remained active. That reporting concerns the company's credential hygiene generally rather than the McHire authorization chain specifically, and the dispute travels with it.
empirical- Investigative Krebs on Security (2025, July). Poor Passwords Tattle on AI Hiring Bot Maker Paradox.ai https://krebsonsecurity.com/2025/07/poor-passwords-tattle-on-ai-hiring-bot-maker-paradox-ai/
- Vendor Paradox.ai (2025, July 9). Responsible Security Update https://www.paradox.ai/blog/responsible-security-update
- Trade press CSO Online (2025). McDonald's AI hiring tool's password '123456' exposed data of 64M applicants https://www.csoonline.com/article/4020919/mcdonalds-ai-hiring-tools-password-123456-exposes-data-of-64m-applicants.html
Workday, Inc. announced a definitive agreement to acquire Paradox.ai on 21 August 2025, seven weeks after the disclosure, and completed the acquisition on 1 October 2025, folding the Olivia assistant into its talent-acquisition suite. Workday's own completion release describes the assistant as a conversational candidate-experience agent handling applications, screening support, self-scheduling, and round-the-clock chat for frontline high-volume roles, and discloses no price. Trade coverage of the transaction carried the McHire incident and Paradox's dispute of its scope as due-diligence context, and recorded Paradox clients including Wendy's, 7-Eleven, and General Motors. The effect on this case is that custody of the same applicant records moved inside a much larger human-capital software company three months after the exposure was disclosed. That acquirer is separately the subject of a different deployment record in this atlas on an unrelated question, and the two are not merged: this case is documented from the June and July 2025 record, when Paradox was independent.
empirical- Vendor Workday, Inc. (2025, October 1). Workday Completes Acquisition of Paradox (newsroom release) https://newsroom.workday.com/2025-10-01-Workday-Completes-Acquisition-of-Paradox
- Trade press HR Dive (2025). Workday pushes AI branding in 'strategic' Paradox acquisition https://www.hrdive.com/news/workday-pushes-ai-branding-in-strategic-paradox-acquisition/758574/
Where this connects
Institutional pressures in this domain
- Workload surge — Demand outruns staffing; per-case attention shrinks and review becomes triage.
- Vendor opacity — The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.
- Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
- Data & policy drift — The world, the intake process, and the rules change under a system trained on how things used to be — two mechanisms with different remedies: the statistical properties of what the system processes move (concept drift), or the mixture of inputs arriving in deployment differs from the mixture it was trained on (covariate shift).
- Reviewer bottleneck — One fixed-capacity checking stage sits between AI output and consequence; everything queues behind it.
All of them in context on the Hiring & employment screening AI domain page.
Levers available here and the patterns behind them
- Vet connections — Connection authorization
- Store less data — Data minimization
- Gate record entries — Human-in-the-loop write gating
- Check copied records — Reconcile copied records
- Understand the system — Understand the system
- Check with a second model — Cross-model verification
- Peer sharing rules — Peer-edge governance
- Gate vendor updates — Vendor quality gate
- Review on schedule — Oversight cadence & retrospectives
- Upgrade model — Improve the model
Documented case histories
- McHire and the 64-million-record custody exposure
- A resume screener that learned the past's bias
- Vendor screening across thousands of employers (litigation live)
- Graduate-hiring AI with its audits on the record
- HireVue video assessment (vendor layer)
- The 1959 statute and the integrity video screen (Baker v. CVS Health)
- An internal promotion, a recorded screen, and a captioning request (D.K. charges against Intuit and HireVue)
- Aon pre-hire assessment suite (vendor's own tables)
- The cooperative audit: a paid source-code examination, and what happened to its verdict
- SiriusXM's iCIMS applicant screening
- Checkr gig-economy background screening
- The rule with no number to disclose
- The account goes dark at nine; the reason arrives on day twenty-six
- iTutorGroup Tutor Application Screen
- Meta Job-Ad Delivery: the guardrail and the layer below