Skip to main content
Emerging ThreatsData Breaches

McDonald's Customer Data Platform Breach Exposes 40M Records

McDonald's restaurant interior with customers, focusing on blurred POS terminal and discarded paper near trash can.

“Affected individuals could face an increase in social engineering attempts via email or scam calls. Moreover, there is a risk of loyalty fraud because of exposed loyalty point transaction information.” — Cybernews team

McDonald’s Indonesia: the scale of the exposure

More than 40 million records stored in a McDonald’s Indonesia customer data platform were exposed, according to the reporting. Of that total, 28 million records were identified as customer records. The exposure also included corporate data: more than 71,000 records related to advertising campaigns were found in the same database.

What was in the customer records

The 28 million customer records contained personally identifiable information explicitly named in the reporting: customer names, email addresses, phone numbers and device IDs. Cybernews, which discovered the exposure, highlighted two concrete risks tied to that data: an increased volume of social engineering attempts via email or scam calls, and the potential for loyalty fraud because loyalty point transaction information was exposed.

Corporate risk: ad campaign records surfaced

Beyond individual customer information, the exposed database held more than 71,000 records concerning ad campaigns. The reporting does not provide further detail on the ad data’s contents, but the presence of campaign records in the same repository is a factual element of the exposure and represents corporate-level information that was placed at risk alongside personal customer records.

Discovery and containment: Cybernews and database closure

The exposure was discovered by the Cybernews team. After discovery, the database was closed and is no longer publicly accessible, according to the report. That sequence — discovery by Cybernews followed by closure of the database — is the response timeline provided in the source material.

What this means for technologists and security teams, affected enterprises and procurement leaders, and end users

  • Technologists and security teams: The incident centers on a customer data platform, and the exposed fields named in the report (names, emails, phone numbers, device IDs, and loyalty point transaction information) are the concrete items security teams will prioritize in forensic review and risk assessments. Cybernews’s explicit warning about social engineering and loyalty fraud will shape incident triage and containment actions.
  • Affected enterprises and procurement leaders: The presence of more than 71,000 ad campaign records in the same database underscores that corporate campaign data can co-reside with customer profiles. Procurement and risk teams responsible for vendor or platform oversight will need to consider how customer data platforms are configured and whether separation controls were in place — the exposure as reported will be a focal point in contract and operational reviews.
  • End users and the general public: Cybernews’s findings name concrete consequences for individuals whose records were exposed — a possible rise in scam emails and calls and a risk of loyalty fraud tied to loyalty point transaction information. Those named risks are the specific, stated harms the reporting identifies for affected customers.

The facts in the reporting are compact but sharp: more than 40 million records exposed, 28 million of them customer records containing names, emails, phone numbers and device IDs, and more than 71,000 ad campaign records found in the same database. The exposure was discovered by Cybernews and the repository has been closed and is no longer accessible. Cybernews’s assessment of likely harms — social engineering and loyalty fraud — is the explicit harm attributed to the exposed fields.

Two clear lines remain visible from the source material: the numerical scale of the exposure, and the concrete, named categories of data at risk. How notification, remediation and any follow-up audits proceed beyond the closure of the database are not described in the material provided; the disclosed record closes with the Cybernews discovery and the database being taken offline.

Source: https://www.securitymagazine.com/articles/102613-40m-mcdonalds-records-exposed-through-customer-data-platform