← Blog

McDonald's Data Breaches: Full Timeline Through 2026

Share on X

People search McDonald's data breach timeline because millions of customers entrust payment and identity data to everyday transactions. BreachHistory indexes 7 McDonald's-linked incidents, with headline counts up to 64M+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.

Why McDonald's breach history matters

McDonald's operates in Retail (United States). Across indexed rows, recurring themes include credential theft and social engineering, zero-day exploitation and malware. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.

Full timeline through 2026

2025 — 64M job applicant records

Cataloged incident. Security researchers discovered catastrophic flaws in McDonald's AI hiring platform McHire (powered by Paradox.ai's Olivia chatbot). An administrator account used default password '123456' with no MFA. IDOR vulnerability allowed access to applicant records by manipulating URL IDs. Exposed: names, emails, phone numbers, resumes, chat transcripts, personality test responses. ~90% of franchises using McHire potentially affected. Exposed categories include Names, emails, phone numbers, resumes, chat transcripts, personality test responses. BreachHistory cites approximately 64M+ affected records in this row. See the mcdonalds2025 and canonical BreachHistory entry.

2021 — — Customer data

Cataloged incident. Hacked. Customer data. Exposed categories include Names, emails, addresses, and other PII. No attested victim count is published for this row yet. See the mcdonalds2021 and canonical BreachHistory entry.

2021 — — MacDonalds: Hacking, 1,000,000 records

Cataloged incident. Unknown detail Exposed categories include Personal and demographic data. BreachHistory cites approximately 1M+ affected records in this row. See the mcdonalds2021-iib and canonical BreachHistory entry.

2013 — — McDonald's: Eleven people were charged with participating in an…

Cataloged incident. Eleven people were charged with participating in an identity theft ring.  Some of the defendants obtained customer credit and debit card information by using skimmers at their places of employment.  Others used the stolen information to make fraudulent payment cards.  The ring was in action between June of 2009 and November of 2010. Exposed categories include Personal information. No attested victim count is published for this row yet. See the mcdonalds2013 and canonical BreachHistory entry.

2012 — — McDonald's: A dishonest McDonald's employee confessed to using…

Cataloged incident. A dishonest McDonald's employee confessed to using a handheld skimming device for three weeks to capture drive-thru customer credit and debit card numbers. He then passed the information along to others who used the numbers to produce fraudulent cards and make purchases.  A total of 282 card numbers were discovered on a suspect's laptop.UPDATE (07/02/2012): The former employee pleaded guilty to an aggravated identity-theft charge.  He agreed to playing a part in causing a total loss of more than Exposed categories include Personal information. BreachHistory cites approximately 282 affected records in this row. See the mcdonalds2012 and canonical BreachHistory entry.

2011 — — McDonald's: A cashier pleaded guilty to conspiracy to commit…

Cataloged incident. A cashier pleaded guilty to conspiracy to commit access device fraud and aggravated identity theft.  The cashier was part of a group of friends who used stolen credit card numbers to make $50,000 in purchases.  The cashier's job was to swipe customer debit and credit cards while working at McDonald's.UPDATE (2/03/2012): The man who was the ring leader of the credit card scam and recruited the McDonald's employee was sentenced to seven years in federal prison on February 3.  He reportedly paid a Exposed categories include Personal information. BreachHistory cites approximately 185 affected records in this row. See the mcdonalds2011 and canonical BreachHistory entry.

2010 — — McDonald's: Hackers were able to access the information of…

Cataloged incident. Hackers were able to access the information of McDonald's customers.  People who signed up for online promotions or newsletter subscriptions may have had their email addresses, contact information and birth dates exposed.  McDonald's uses a company called Arc Worldwide for its marketing services.  The breach was through Arc Worldwide's business partner Silverpop Systems Inc. Exposed categories include Personal information. No attested victim count is published for this row yet. See the mcdonalds2010 and canonical BreachHistory entry.

Patterns and analysis

  • Credential theft and social engineering — appears across multiple McDonald's catalog entries; prioritize controls that address this class of failure.
  • Zero-day exploitation and malware — appears across multiple McDonald's catalog entries; prioritize controls that address this class of failure.
  • Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
  • 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.

What to do if you may be affected

  1. Step 1: Enable phishing-resistant MFA on every account tied to this brand.
  2. Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
  3. Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
  4. Step 4: Use virtual card numbers for online checkout where your bank supports it.
  5. Step 5: Bookmark the McDonald's company page for new 2026+ disclosures.

Canonical BreachHistory hub

Explore every indexed row: breachhistory.com/mcdonalds · Latest: mcdonalds2025.

Sources: BreachHistory catalog (7 rows for McDonald's), company and regulator disclosures cited in individual breach records.