McDonald's Indonesia left a MongoDB database attached to its Customer Data Platform (CDP) open to the internet. Cybernews researchers say it held more than 40 million records, and about 28 million of them contained customers' personal details: names, email addresses, phone numbers and device IDs. Loyalty card and sales data were also in the database. Almost all of what is known comes from the Cybernews research team, which found the database and reported that it has since been closed. We found no statement from McDonald's Indonesia, no regulator filing and no CERT advisory. Cybernews says it asked the company for comment and has not had a reply. Treat the figures below as the researchers' numbers, not company-confirmed ones. This is a misconfiguration exposure, not a known intrusion. No threat actor has claimed it, and no source says the data was downloaded by anyone other than the researchers.
What Happened
Cybernews reports that its research team found a publicly reachable MongoDB instance belonging to McDonald's Indonesia. The database backed the company's Customer Data Platform, which gathers customer identity, loyalty and transaction data in one place. It needed no authentication, so "anyone caring to look" could read it, in the researchers' words.
After the researchers reported it, McDonald's Indonesia closed public access to the database. The sources do not say how long it was open, when it was first indexed, or whether anyone else accessed it before it was closed. Those are the main open questions. Without server access logs, which only the company can check, nobody can rule out earlier scraping by third parties.
Several other McDonald's incidents are in the news at the same time. They are separate and should not be merged with this one:
- Azure/Entra employee directory sale (August 2026). A seller calling themselves "TheHatman" is advertising more than 1.7 million records said to come from McDonald's Corporation's Azure tenant. It is part of a nine-company listing that also names Vodafone, TCS, Kyndryl and others (TechRadar, The Cyber Signal, SQ Magazine, InfoSecBulletin). The data is employee directory data, not customer data. It was reportedly taken with stolen credentials, and McDonald's has not confirmed it. Ransomnews, cited by ITSecurityNewsBox, analysed an 8,000-row sample and found it looks genuine, but could not confirm how old it is or whether the full 1.7 million figure is real.
- McHire / "Olivia" chatbot exposure. A vendor blog (CallerVerify) describes more than 60 million job-applicant records exposed through McDonald's AI hiring platform because of default credentials. It is a different system, a different dataset and a different time period.
- Arc Worldwide promotions breach (2010). The Next Web reported that a marketing partner's systems were compromised, exposing names, emails, phone numbers and postal addresses of people who signed up for promotions on McDonald's websites.
None of these sources links the Indonesian CDP exposure to the Azure campaign, the McHire incident, or any other event.
What Was Taken
Cybernews reports more than 40 million exposed records in total, most of them customer-related. About 28 million are customer profile records. No other source gives a figure for this incident, so there is no range to report. Both numbers come from one research team and have not been independently verified or confirmed by the company.
Data types reported in the database:
- Customer identity data: full names, email addresses, phone numbers
- Device identifiers: device IDs tied to customer profiles, probably from the mobile app
- Loyalty program data: loyalty card records and loyalty point transaction history
- Sales and transaction data: purchase information linked to customers
The sources do not mention passwords, payment card numbers or government ID numbers. On current reporting, the data is sensitive because of how many people it covers and how the records link together. It is not high-value credential material. Names, contact details, device IDs and purchase history all linked in one record make a very good base for targeted fraud.
Why It Matters
Scale in a single market. Twenty-eight million customer profiles is a large share of McDonald's Indonesia's app and loyalty user base. Indonesia's Personal Data Protection Law (UU PDP) sets out breach notification duties. Whether McDonald's Indonesia has notified the regulator or the affected customers is not stated in any source.
Fraud is the main risk. Cybernews warns that affected customers are likely to see more phishing emails and scam calls. It also warns of loyalty fraud, because the exposed point transaction data shows which accounts hold balances worth stealing. A scammer who can quote someone's name, phone number and recent orders sounds far more convincing than one working from a generic list.
CDPs concentrate risk. A customer data platform exists to join identity, device, loyalty and transaction data together. One misconfigured instance therefore exposes a full profile of each customer. Defenders should treat CDP datastores with the same care as their most sensitive production systems.
The brand is under pressure from several directions. In the same period, McDonald's has been named in a claimed Azure directory theft (1.7M employee records, unconfirmed) and a hiring-platform exposure (60M+ applicant records, per CallerVerify). The causes differ: a misconfigured database, stolen credentials, and default passwords. The pattern is the same, though. Large global brands with many franchisees and many third-party platforms have a wide and uneven attack surface, and the weakest parts are usually regional deployments and vendor-run systems.
The Attack Technique
There was no attack in the usual sense. According to Cybernews, the database was simply exposed: a MongoDB instance reachable from the public internet with no working access control. Attackers routinely find this kind of misconfiguration with internet-wide scanners such as Shodan and Censys, or with their own scripts. Exposed MongoDB instances are a common target for automated data theft and extortion campaigns that copy the data, wipe the collections and leave a ransom note.
What is not known:
- How long the database was exposed
- Whether it was accessed by anyone besides the Cybernews researchers
- Whether McDonald's Indonesia runs the database itself or through a third-party CDP vendor or integrator
- Whether any of the data has appeared on criminal forums (no source reports that it has)
The Azure/Entra incident reported in August worked differently. There, the seller says they logged in with valid credentials, and Hudson Rock linked those credentials to infostealer infections on employee devices. We have no evidence that the two incidents are connected.
What Organizations Should Do
- Continuously scan your external attack surface for exposed datastores. Run automated external discovery for MongoDB, Elasticsearch, Redis and cloud storage buckets across every region, subsidiary and franchise operator, not only corporate headquarters. Regional marketing and CDP deployments are often outside central security review.
- Enforce authentication and network isolation on every database. Bind database services to private interfaces, require authentication, and put them behind a VPN or private endpoints. Treat any production data store without authentication as a critical finding.
- Treat CDP and loyalty platforms as crown-jewel systems. Put them in your data classification scheme, apply least-privilege access, log all queries, and alert on bulk reads or exports. Loyalty balances are effectively stored value, so detect account takeover and point theft as you would payment fraud.
- Put configuration security in third-party and franchise contracts. Require partners who run customer data platforms to meet baseline configuration controls, keep access logs, and notify you of breaches within a defined time.
- Prepare customers for targeted phishing. After an exposure like this, warn customers directly: the company will never ask for passwords, OTPs or payment details by phone or email. Watch for lookalike domains and SMS campaigns that use the brand.
- Check logs before declaring the incident contained. Closing the database stops future access but does not show whether anyone took data earlier. Keep and review access logs for the full exposure window, and let that evidence decide whether regulators and customers must be notified.
Sources: McDonald's data leak exposes 28 million customer details Cybernews | Like Gawker, McDonalds targeted by hackers. | Millions of stolen records allegedly dumped online by mystery "Hatm... | Azure Data Theft: McDonald's, Vodafone, TCS, Kyndryl Named | McDonald’s Employee Data Appears in Leak, Seller Claims 1.7M Record... | McHacked: What the 60-Million McDonald’s Chatbot Breach Reveals Abo... | Azure Data Breach Hits McDonald's, Vodafone, TCS, More | McDonald’s, Vodafone Affected by Azure Theft Campaign Exposing Mill...