McDonald's India App Leaked Customer Data, Millions Said to Be Impacted

Advertisement
By Kunal Dua | Updated: 19 March 2017 12:26 IST
Highlights
  • The McDelivery app leaked personal information of McDonald's customers
  • Users in South & West regions impacted
  • McDonald's did not deny the leak; said no financial information stored

McDonald's India app McDelivery leaked personal information of its customers for an unspecified duration of time, Cybersecurity firm Fallible reported on Saturday. This included "name, email address, phone number, home address, accurate home co-ordinates, and social profile links" for "more than 2.2 million" of its users.

According to a blog post published by the firm, "an unprotected publicly accessible API endpoint for getting user details coupled with serially enumerable integers as customer IDs can be used to obtain access to all users personal information." Gadgets 360 was able to independently verify this claim using information provided by the firm to access data of some customers.

It's worth pointing out that McDonald's operations in India are split into two entities - McDonald's India (West & South) and McDonald's India (North & East), and the McDelivery app and website are owned and operated by the former entity. Customers in North and East of India use another app and website, so their data doesn't seem to be impacted by this leak.

Advertisement

Fallible says it first reported the issue to McDonald's India on February 4, though it's possible the leak has been around for much longer. It's unclear at this point if anyone else knew about the leak and if they were able to exploit it to download data of all McDonald's India (West & South) customers. The leak remained unplugged hours after Fallible's blog post was published, so if the data hadn't been accessed earlier, it could've certainly been downloaded since.

Advertisement

At the time of publishing this post, McDonald's seems to have plugged the hole that we used to access user data, but Fallible says "The McDonald's fix is incomplete and the endpoint is still leaking data. We have communicated this again to them and are waiting for their response."

An official spokesperson for McDonald's India (West & South), the company that owns and operates the McDelivery app, sent the following statement to Gadgets 360:

Advertisement

We would like to inform our users that our website and app does not store any sensitive financial data of the users like credit card details, wallets passwords or bank account information. The website and app has always been safe to use, and we update security measure on regular basis. As a precautionary measure, we would also urge our users to update the McDelivery app on their devices.

As is clear from the statement, the company does not deny that personal information was being leaked; instead it's just highlighting the fact that the company stores no financial information of the users - as if that's supposed to make customers feel better. Unfortunately, in the absence of strong data privacy and protection laws, customers in India have no real recourse but to get on with their lives.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo F31 Series Launched With 7,000mAh Battery: Check Price, Features
  2. Nothing Announces Offers on Phones, Wearables During Flipkart Sale
  3. Vivo Y31 Series With 6,500mAh Battery Launched in India: See Price
  4. iOS 26 Update for iPhone Releases Today: Everything You Need to Know
  5. Realme P3 Lite 5G With 6,000mAh Battery Launched in India at This Price
  6. Butterfly-Shaped Hole in the Sun Could Spark Solar Storms Worldwide
  7. Flipkart Big Billion Days Sale: Discounts on Motorola Phones Announced
  8. iQOO 15 Live Image Leaked; Company Reveals Display Details
  9. Oppo Find X9 Launch Timeline Revealed: See Find X9 Pro Camera Samples
  10. Apple Might Launch the iPhone 17e and Nine Other New Products by Early 2026
  1. Resident Evil Requiem, Resident Evil 7: Biohazard and Resident Evil Village Are Coming to Switch 2 Next Year
  2. iQOO 15 Live Image Hints at Design; Confirmed to Feature 2K Samsung AMOLED Display
  3. Vivo Y31 Pro 5G, Vivo Y31 5G Launched in India With 6,500mAh Battery, 50-Megapixel Camera: Price, Features
  4. [Exclusive] Noise to Launch Flagship Master Series Over-Ear Headphones With Dynamic EQ
  5. Flipkart Big Billion Days Sale 2025: Motorola Edge 60 Pro, Edge 60 Fusion, Moto G96 5G and More to Get Discounts
  6. Snapdragon 8 Elite Gen 5 Confirmed to Launch as Qualcomm's Upcoming Flagship Mobile Chipset
  7. Flipkart Big Billion Days Sale: Nothing Announces Offers on Phone 3a Pro, CMF Phone 2 Pro, Nothing Ear, and More
  8. Bitcoin Steadies Above $116,400 as Ether and Other Altcoins Show Resilience
  9. Oppo F31 Pro+ 5G Launched in India With 7,000mAh Battery Alongside Oppo F31 Pro 5G, F31 5G: Price, Features
  10. Apple Reportedly Plans to Launch iPhone 17e, MacBook Air M5, and More Products by Early 2026
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.