Skip to main content
Back to overview
High

McDonald's India Delivery System Exposed Customer and Driver Data

A major McDonald’s delivery system in India exposed the personal information of its customers and drivers due to several simple security flaws, TechCrunch has exclusively learned.

Key points

  • McDonald's India delivery system exposed personal information.
  • Security flaws in APIs were the cause.
  • Affected both customers and drivers.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Threat source not confirmed

03

Potential impact

Service Disruption

Confidentiality, Availability

Published
Dec 19, 2024
Updated
Jul 22, 2026
Confidence
High
Evidence
1 source

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch ransomware, endpoint compromise and business interruption exposure.

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data

Mentioned entities

McdonaldsData DisclosureMcDonaldIndiaTechCrunchTraceable AIEaton ZveareAPIs of theWestSouth

Quick context

Questions about this signal

What happened in this signal?

A major McDonald’s delivery system in India exposed the personal information of its customers and drivers due to several simple security flaws, TechCrunch has exclusively learned. The flaws, discovered by Traceable AI security researcher Eaton Zveare, were found in the APIs of the delivery system associated with McDonald’s India (West & South) , which is owned by Hardcastle Restaurants. Zveare exclusively told TechCrunch that bugs in the company’s delivery system, McDelivery, meant anyone could access, hijack, redirect, or real-time track orders, or make legitimate orders for $0.01, by interacting with the company’s API, which apps and websites use for placing orders and tracking. This is because the API wasn’t properly checking to make sure the person making requests was allowed to make requests. The bugs also allowed access to invoices and provided the ability to submit feedback for customer orders. The security flaws exposed McDelivery customer full names, email addresses, and phone numbers of McDonald’s India (West & South) customers, and exposed access to vehicle numbers, profile pictures, and tracked the real-time location of the restaurant chain’s drivers delivering orders. In a since-published blog post , Zveare found the vulnerabilities and reported them to the restaurant chain in July. They were fixed in late September, per the researcher. McDonald’s India told TechCrunch that a “thorough verification of systems and logs” showed the flaws did not result in a breach of its customer data. “We conduct regular audits and assessments to continuously strengthen our security measures, and have all the necessary enhancements implemented, ensuring all our systems are up to date and secure,” Sulakshna Mukherjee, a spokesperson at McDonald’s India (West & South), said in a statement emailed to TechCrunch. McDonald’s India did not disclose the number of customers whose information may have been exposed by the bugs. However, the researcher told TechCrunch that the flaws exposed access to hundreds of millions of orders. “The McDelivery (West & South) mobile app uses the same exact back-end APIs as the website. As a result, both were vulnerable to the same exploits,” the researcher told TechCrunch. This is not the first time McDonald’s India has exploited its customers’ sensitive data. In 2017, the delivery app of McDonald’s India (West & South) leaked the personal information of about 2.2 million customers. When you purchase through links in our articles, we may earn a small commission . This doesn’t affect our editorial independence. Jagmeet covers startups, tech policy-related updates, and all other major tech-centric developments from India for TechCrunch. He previously worked as a principal correspondent at NDTV. You can contact or verify outreach from Jagmeet by emailing mail@journalistjagmeet.com . View Bio October 13 – 15 San Francisco Scale faster. Grow your portfolio. Gain practical expertise. No matter your goal, Disrupt can empower you. Save up to $330 toda y! AI music generator Suno breach affects 55M users, per Have I Been Pwned Anthropic’s landmark $1.5B copyright settlement is approved Judge pauses $110B Paramount-Warner Bros. merger Apple and Google ordered to purge ‘nudify’ apps from App Stores Coca-Cola suspended production at its Fairlife dairy after a ransomware attack Tesla driver in fatal Texas crash pressed accelerator 100%, NTSB confirms Amid hardware legal battle, OpenAI releases a $230 keyboard for Codex

When was this signal reported?

Shadow Tier lists Dec 19, 2024 as the signal date.

Which organization is connected to this signal?

Mcdonalds is the organization connected to this public signal.

Explore Mcdonalds
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents
Which impact area is relevant?

This signal is connected to cyber service disruption intelligence based on its reported consequences.

Explore cyber service disruption intelligence