SHINDO3

McDonald's

Email addresses affected8,989records

LEAK CONFIRMEDMisdelivery · Closed (final report)

Open in the live monitor ▶
Disclosed
Mar 21, 2025
Leak
Leak confirmed
Type
Misdelivery
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced

What leaked

ContactEmail address

How many

  • Email addresses affected 8,989 records

Who is affected

  • Customers who newly registered on the McDonald's official app

Cause

A setting error in the email delivery system put other, unrelated customers' email addresses in the recipient field of sign-up confirmation emails

Timeline

  1. Exposure began
  2. Exposure ended
  3. Reported to authority
  4. Date of the Security NEXT report

Response

  • Notified individuals
  • Data deleted
  • Change process

Apologized to affected customers and asked them to delete the email. Reviewing the email delivery system and strengthening checks before sending

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Check the company's notice to see if you're affected

Lessons for companies

  1. Use DLP: recipient checks, send delay, automatic attachment protection
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources