logo

Bugs in a major McDonald’s India delivery system exposed sensitive customer data

ID: c5bd0417-f03f-5b21-8f1f-8c5ab13764b4

STIX ID: report--c5bd0417-f03f-5b21-8f1f-8c5ab13764b4

Feed Name: TechCrunch Security News

Threat Score
70/100

Date Published: 2024-12-19

Date Updated: 2026-04-23

Author: Jagmeet Singh

...
...

Researcher-discovered insecure APIs in McDelivery (McDonald’s India West & South) allowed unauthorized access to customers' full names, emails, phone numbers, driver vehicle numbers, profile pictures, and real-time driver locations, and enabled order hijacking and creation of nearly free orders; the issues were reported in July and fixed in late September, with McDonald’s stating logs show no confirmed breach.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.