# How '123456' Helped Hack McDonald's

Source: https://www.youtube.com/watch?v=QMMRelIafo4
Recap page: https://rapidrecap.app/video/QMMRelIafo4
Generated: 2025-07-10T18:58:38.396+00:00

---
## Quick Overview

McDonald's McHire platform was breached due to a simple '123456' password on an admin account, exposing personal data of over 64 million job applicants. Additionally, a Brazilian bank heist of over $100 million occurred after an employee sold credentials for $2,700, and the CatWatchful spyware app was hacked, leaking 62,000 user accounts and plaintext passwords.

## Summary

**Key Points:**
- McDonald's McHire platform was breached via an admin account using the simple password '123456'.
- The breach exposed personal data (names, emails, phone numbers, addresses) of over 64 million McDonald's job applicants.
- A Brazilian bank heist of over $100 million was facilitated by an employee who sold his corporate credentials for $2,700.
- Hackers drained central bank reserve accounts of six financial institutions in Brazil.
- The CatWatchful spyware app was hacked, leaking email addresses and plaintext passwords for 62,000 user accounts.
- The CatWatchful hack was due to an unauthenticated API and an SQL injection vulnerability.

**Context:** This video details three recent cybersecurity incidents: a data breach at McDonald's hiring platform, a large-scale bank heist in Brazil, and the hacking of a spyware application. Each incident highlights different vulnerabilities, from weak passwords and API flaws to insider threats and outdated security practices, demonstrating the diverse methods cybercriminals employ and the broad impact of such breaches.

## Detailed Analysis

McDonald's McHire, a talent hiring platform used by 90% of its franchisees, suffered a significant data breach. Security researchers discovered that an admin account was accessible with the default password '123456', bypassing multi-factor authentication. This access allowed them to exploit an API vulnerability, enabling them to retrieve personal information (names, email addresses, phone numbers, and physical addresses) of over 64 million job applicants who had applied since 2019, regardless of the specific restaurant they were logged into. This exposed applicants to potential phishing attacks. In a separate incident, a Brazilian bank heist of over $100 million was facilitated by a C&M Software employee, João Nazareno Roque, who sold his corporate login credentials for approximately $2,700 to cybercriminals. This allowed hackers to drain central bank reserve accounts of six financial institutions. Authorities managed to freeze about $55 million, but $30-40 million was converted to crypto, and the masterminds remain at large. Finally, the CatWatchful Android spyware app, marketed for parental control but often used for stalking, was hacked. A security researcher found an unauthenticated API and an SQL injection vulnerability, leading to the dump of the entire database, which contained email addresses and plaintext passwords for approximately 62,000 user accounts. The developer, Omar Soca Charcov, did not respond to inquiries, and the CatWatchful website has since vanished.

### McDonald's McHire Breach

- An admin account on McDonald's McHire platform was accessible with the default password '123456'
- Researchers exploited an API vulnerability to access personal data of over 64 million job applicants (names, emails, phone numbers, addresses)
- The exposed data, collected since 2019, creates a significant risk for phishing attacks
- The platform's developer, Paradox.ai, resolved the issue after disclosure but initially lacked clear security contacts.

### Brazilian Bank Heist

- A Brazilian bank heist of over $100 million occurred through C&M Software, which connects financial institutions to Brazil's Central Bank
- An employee, João Nazareno Roque, sold his corporate credentials for R$15,000 (approx. $2,700) to cybercriminals
- Hackers drained hundreds of millions of Brazilian Reals from central bank reserve accounts of six financial institutions
- Authorities froze approximately $55 million, but $30-40 million was converted to crypto, and the main perpetrators are still at large.

### CatWatchful Spyware Hack

- CatWatchful, an Android spyware app marketed for parental control, was found to have critical vulnerabilities
- A security researcher discovered an unauthenticated API and an SQL injection flaw
- The entire database was dumped, exposing email addresses and plaintext passwords for approximately 62,000 CatWatchful user accounts
- The developer did not respond to inquiries, and the CatWatchful website has since disappeared, following a trend of hacked stalkerware tools.

![Screenshot at 0:02: McHire login screen with password field](https://ss.rapidrecap.app/screens/QMMRelIafo4/00-00-02.png)
![Screenshot at 0:06: Man in McDonald's hat with large number](https://ss.rapidrecap.app/screens/QMMRelIafo4/00-00-06.png)
![Screenshot at 0:14: CatWatchful website with glitch effect](https://ss.rapidrecap.app/screens/QMMRelIafo4/00-00-14.png)
![Screenshot at 1:45: McHire admin dashboard showing employee list](https://ss.rapidrecap.app/screens/QMMRelIafo4/00-01-45.png)
![Screenshot at 2:07: McHire candidate inbox with highlighted data](https://ss.rapidrecap.app/screens/QMMRelIafo4/00-02-07.png)
![Screenshot at 2:30: API request showing 'lead_id' parameter](https://ss.rapidrecap.app/screens/QMMRelIafo4/00-02-30.png)
![Screenshot at 3:04: Bullet points listing leaked data types](https://ss.rapidrecap.app/screens/QMMRelIafo4/00-03-04.png)
![Screenshot at 4:12: News headline about hacker attack on C&M Software](https://ss.rapidrecap.app/screens/QMMRelIafo4/00-04-12.png)
![Screenshot at 4:41: LinkedIn profile of João Nazareno Roque](https://ss.rapidrecap.app/screens/QMMRelIafo4/00-04-41.png)
![Screenshot at 8:10: Table showing leaked plaintext passwords](https://ss.rapidrecap.app/screens/QMMRelIafo4/00-08-10.png)
