// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-newsDTG 0600Z
ColdRecon / Breach Radar / McDonald's
Breach Record

McDonald's

DISCLOSED 2026-10-01 · MISCONFIG · 40,000,000 RECORDS EXPOSED

A database containing 40 million McDonald's customer records was publicly accessible due to a misconfiguration. The exposure included loyalty point transaction information and ad campaign records. The database has since been secured.

The record

What we know

Disclosed
2026-10-01
Attack vector
Misconfig
Sector
Food & Beverage
Country
USA
Records exposed
40,000,000
Domain
mcdonalds.com
Data classes exposed
customer dataloyalty point transaction informationad campaign records
ColdRecon assessment

Could a positive-security control have prevented this?

Verdict · would prevent · opinion

OPINION: A positive-security model that snapshots known-good configurations and rejects unauthorized changes would have prevented this exposure by detecting and blocking the misconfigured public access to the database.

Our assessments are opinion, grounded in the cited public facts. Read them critically.

Sources

Cited reporting

Similar vector · recent

Other misconfig breaches on file

This page is the permanent ColdRecon entry for the McDonald's disclosure. It updates if new public reporting emerges. All tracked breaches →

McDonald's just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →