64 million people applied for jobs. Their passwords, personality tests, and private chat logs were exposed — because the admin password was "123456."
Not a Hollywood hacking scene. Not a nation-state attack. Just a six-digit default password that nobody changed for six years.
This actually happened. McDonald's AI hiring platform, built by a vendor called Paradox.ai, left a management portal wide open with those exact credentials. No multi-factor authentication. No account review since 2019.
Once researchers got in through that front door, they found a second flaw — they could pull up any applicant's full record just by changing a number in the URL. Names, emails, phone numbers, interview transcripts, even personality assessment results.
Think about that for a second. Millions of people shared deeply personal information with an AI chatbot during one of the most vulnerable moments of their lives — applying for a job. And the system holding all of that data was protected by the same password people use on luggage locks.
Here's what stuck with us: you can build the most sophisticated AI in the world, but if the infrastructure around it runs on default credentials and unpatched APIs, the AI isn't the problem. The neglect is.
We wrote a full breakdown covering the technical failure, the psychological harm of leaked psychometric data, and a layered defense framework for companies deploying AI at scale.
Honest question for this community — when you hand over personal information to an AI system (hiring, banking, healthcare), do you generally trust that it's being protected? Or do you just hope for the best?
#AISecurity #DataPrivacy #DeepAI
Published on Facebook · March 2, 2026
On social media
See this post on its original platform
In our archive