
McDonald's Indonesia Data Leak Exposes Over 40 Million Records
McDonald's Indonesia exposed a MongoDB database containing over 40 million records, including 28 million customer records with emails, names, phone numbers, and device IDs. The company has closed the exposed database.
McDonald's Indonesia has exposed its Customer Data Platform, leaking over 40 million records online, most of them related to customers. The exposed MongoDB database contained loyalty card data, sales information, customer details, and other data points left available to anyone who looked.
What data was exposed?
The largest group of leaked records includes over 28 million entries containing personal identifiable information. This covers around 12.6 million personal email addresses, 12.5 million full names, about 1 million phone numbers, and roughly 28.15 million last known device IDs.
The database also held over 12 million GDPR consent event logs and snapshots across two collections, revealing user IDs, consent flags, and timestamps. Loyalty card data and loyalty point transaction logs totaled over 226,000 records across five collections, including reporting IDs, transaction IDs, transaction types, and their timestamps.
Corporate details were also exposed. Researchers found over 71,000 records on ad campaigns containing titles, statuses, timestamps, and user interaction data, along with 37,800 sales records, several hundred records on McDonald's Indonesia locations, and push notification data.
What risks does the leak pose?
Researchers warn that attackers could use the exposed records for scams, account impersonation, and loyalty fraud. With customer names, email addresses, phone numbers, device IDs, loyalty identifiers, transaction histories, and consent logs, attackers could build detailed profiles of individual users and map their interactions with McDonald's systems over time.
That visibility could enable targeted social engineering, including convincing account recovery requests, fake customer support outreach, and loyalty account abuse that could escalate into financial fraud. Behavioral profiling based on order activity, timestamps, venues, and campaign engagement data could help attackers identify frequent customers and time scams for greater credibility. Device identifiers and consent histories could also be used to make fraudulent messages appear more legitimate by impersonating real platforms, notifications, or privacy actions.
Response and timeline
McDonald's Indonesia has closed the exposed database, meaning it is no longer accessible to the public. Researchers have reached out for comment and say they will update the story once a reply is received. The leak was discovered on July 13, 2026, initially disclosed on July 15, 2026, and observed closed on September 23, 2026.
McDonald's is a frequent target of cybercriminals as its numerous locations aggregate troves of data. In early 2026, ransomware gang Everest Group claimed an attack on McDonald's India, demanding a ransom or threatening to leak stolen data online. In 2025, McHire, McDonald's hiring chatbot platform, exposed 64 million job applicants after its systems were found to be protected by the default password "123456".
Sources: Cybernews
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.