How '123456' Helped Hack McDonald's
Quick Overview
McDonald's McHire platform was breached due to a simple '123456' password on an admin account, exposing personal data of over 64 million job applicants. Additionally, a Brazilian bank heist of over $100 million occurred after an employee sold credentials for $2,700, and the CatWatchful spyware app was hacked, leaking 62,000 user accounts and plaintext passwords.
Summary
Key Points: McDonald's McHire platform was breached via an admin account using the simple password '123456'. The breach exposed personal data (names, emails, phone numbers, addresses) of over 64 million McDonald's job applicants. A Brazilian bank heist of over $100 million was facilitated by an employee who sold his corporate credentials for $2,700. Hackers drained central bank reserve accounts of six financial institutions in Brazil. The CatWatchful spyware app was hacked, leaking email addresses and plaintext passwords for 62,000 user accounts. The CatWatchful hack was due to an unauthenticated API and an SQL injection vulnerability.
Context: This video details three recent cybersecurity incidents: a data breach at McDonald's hiring platform, a large-scale bank heist in Brazil, and the hacking of a spyware application. Each incident highlights different vulnerabilities, from weak passwords and API flaws to insider threats and outdated security practices, demonstrating the diverse methods cybercriminals employ and the broad impact of such breaches.
Detailed Analysis
McDonald's McHire, a talent hiring platform used by 90% of its franchisees, suffered a significant data breach. Security researchers discovered that an admin account was accessible with the default password '123456', bypassing multi-factor authentication. This access allowed them to exploit an API vulnerability, enabling them to retrieve personal information (names, email addresses, phone numbers, and physical addresses) of over 64 million job applicants who had applied since 2019, regardless of the specific restaurant they were logged into. This exposed applicants to potential phishing attacks. In a separate incident, a Brazilian bank heist of over $100 million was facilitated by a C&M Software employee, João Nazareno Roque, who sold his corporate login credentials for approximately $2,700 to cybercriminals. This allowed hackers to drain central bank reserve accounts of six financial institutions. Authorities managed to freeze about $55 million, but $30-40 million was converted to crypto, and the masterminds remain at large. Finally, the CatWatchful Android spyware app, marketed for parental control but often used for stalking, was hacked. A security researcher found an unauthenticated API and an SQL injection vulnerability, leading to the dump of the entire database, which contained email addresses and plaintext passwords for approximately 62,000 user accounts. The developer, Omar Soca Charcov, did not respond to inquiries, and the CatWatchful website has since vanished.