Cyber & AI intelligence
Wasteland.
Briefs indexed2945
Issues30
Published Mondays07:30 CT
▣ Breach MCDONALDS-INDONESI 2026-09-30

McDonald's Indonesia: Exposed MongoDB Database Leaks 28 Million Customer Records

"McDonald's Indonesia left a MongoDB database attached to its Customer Data Platform (CDP) open to the internet. Cybernews researchers say it held more than 40 million records, and about 28 million of them contained…"

McDonald's Indonesia left a MongoDB database attached to its Customer Data Platform (CDP) open to the internet. Cybernews researchers say it held more than 40 million records, and about 28 million of them contained customers' personal details: names, email addresses, phone numbers and device IDs. Loyalty card and sales data were also in the database. Almost all of what is known comes from the Cybernews research team, which found the database and reported that it has since been closed. We found no statement from McDonald's Indonesia, no regulator filing and no CERT advisory. Cybernews says it asked the company for comment and has not had a reply. Treat the figures below as the researchers' numbers, not company-confirmed ones. This is a misconfiguration exposure, not a known intrusion. No threat actor has claimed it, and no source says the data was downloaded by anyone other than the researchers.

What Happened

Cybernews reports that its research team found a publicly reachable MongoDB instance belonging to McDonald's Indonesia. The database backed the company's Customer Data Platform, which gathers customer identity, loyalty and transaction data in one place. It needed no authentication, so "anyone caring to look" could read it, in the researchers' words.

After the researchers reported it, McDonald's Indonesia closed public access to the database. The sources do not say how long it was open, when it was first indexed, or whether anyone else accessed it before it was closed. Those are the main open questions. Without server access logs, which only the company can check, nobody can rule out earlier scraping by third parties.

Several other McDonald's incidents are in the news at the same time. They are separate and should not be merged with this one:

None of these sources links the Indonesian CDP exposure to the Azure campaign, the McHire incident, or any other event.

What Was Taken

Cybernews reports more than 40 million exposed records in total, most of them customer-related. About 28 million are customer profile records. No other source gives a figure for this incident, so there is no range to report. Both numbers come from one research team and have not been independently verified or confirmed by the company.

Data types reported in the database:

The sources do not mention passwords, payment card numbers or government ID numbers. On current reporting, the data is sensitive because of how many people it covers and how the records link together. It is not high-value credential material. Names, contact details, device IDs and purchase history all linked in one record make a very good base for targeted fraud.

Why It Matters

Scale in a single market. Twenty-eight million customer profiles is a large share of McDonald's Indonesia's app and loyalty user base. Indonesia's Personal Data Protection Law (UU PDP) sets out breach notification duties. Whether McDonald's Indonesia has notified the regulator or the affected customers is not stated in any source.

Fraud is the main risk. Cybernews warns that affected customers are likely to see more phishing emails and scam calls. It also warns of loyalty fraud, because the exposed point transaction data shows which accounts hold balances worth stealing. A scammer who can quote someone's name, phone number and recent orders sounds far more convincing than one working from a generic list.

CDPs concentrate risk. A customer data platform exists to join identity, device, loyalty and transaction data together. One misconfigured instance therefore exposes a full profile of each customer. Defenders should treat CDP datastores with the same care as their most sensitive production systems.

The brand is under pressure from several directions. In the same period, McDonald's has been named in a claimed Azure directory theft (1.7M employee records, unconfirmed) and a hiring-platform exposure (60M+ applicant records, per CallerVerify). The causes differ: a misconfigured database, stolen credentials, and default passwords. The pattern is the same, though. Large global brands with many franchisees and many third-party platforms have a wide and uneven attack surface, and the weakest parts are usually regional deployments and vendor-run systems.

The Attack Technique

There was no attack in the usual sense. According to Cybernews, the database was simply exposed: a MongoDB instance reachable from the public internet with no working access control. Attackers routinely find this kind of misconfiguration with internet-wide scanners such as Shodan and Censys, or with their own scripts. Exposed MongoDB instances are a common target for automated data theft and extortion campaigns that copy the data, wipe the collections and leave a ransom note.

What is not known:

The Azure/Entra incident reported in August worked differently. There, the seller says they logged in with valid credentials, and Hudson Rock linked those credentials to infostealer infections on employee devices. We have no evidence that the two incidents are connected.

What Organizations Should Do

  1. Continuously scan your external attack surface for exposed datastores. Run automated external discovery for MongoDB, Elasticsearch, Redis and cloud storage buckets across every region, subsidiary and franchise operator, not only corporate headquarters. Regional marketing and CDP deployments are often outside central security review.
  2. Enforce authentication and network isolation on every database. Bind database services to private interfaces, require authentication, and put them behind a VPN or private endpoints. Treat any production data store without authentication as a critical finding.
  3. Treat CDP and loyalty platforms as crown-jewel systems. Put them in your data classification scheme, apply least-privilege access, log all queries, and alert on bulk reads or exports. Loyalty balances are effectively stored value, so detect account takeover and point theft as you would payment fraud.
  4. Put configuration security in third-party and franchise contracts. Require partners who run customer data platforms to meet baseline configuration controls, keep access logs, and notify you of breaches within a defined time.
  5. Prepare customers for targeted phishing. After an exposure like this, warn customers directly: the company will never ask for passwords, OTPs or payment details by phone or email. Watch for lookalike domains and SMS campaigns that use the brand.
  6. Check logs before declaring the incident contained. Closing the database stops future access but does not show whether anyone took data earlier. Keep and review access logs for the full exposure window, and let that evidence decide whether regulators and customers must be notified.

Sources: McDonald's data leak exposes 28 million customer details Cybernews | Like Gawker, McDonalds targeted by hackers. | Millions of stolen records allegedly dumped online by mystery "Hatm... | Azure Data Theft: McDonald's, Vodafone, TCS, Kyndryl Named | McDonald’s Employee Data Appears in Leak, Seller Claims 1.7M Record... | McHacked: What the 60-Million McDonald’s Chatbot Breach Reveals Abo... | Azure Data Breach Hits McDonald's, Vodafone, TCS, More | McDonald’s, Vodafone Affected by Azure Theft Campaign Exposing Mill...