password – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Sat, 12 Jul 2025 02:51:12 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.9 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 password – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 ‘123456’ password exposed chats for 64 million McDonald’s job applicants https://earlybirdsinvest.com/123456-password-exposed-chats-for-64-million-mcdonalds-job-applicants/ https://earlybirdsinvest.com/123456-password-exposed-chats-for-64-million-mcdonalds-job-applicants/#respond Sat, 12 Jul 2025 02:51:12 +0000 https://earlybirdsinvest.com/123456-password-exposed-chats-for-64-million-mcdonalds-job-applicants/

McDonald's sign

Cybersecurity researchers discovered a vulnerability in McHire, McDonald’s chatbot job application platform, that exposed the chats of more than 64 million job applicants across the United States.

The flaw was discovered by security researchers Ian Carroll and Sam Curry, who found that the ChatBot’s admin panel utilized a test franchise that was protected by weak credentials of a login name “123456” and a password of “123456”.

McHire, powered by Paradox.ai and used by about 90% of McDonald’s franchisees, accepts job applications through a chatbot named Olivia. Applicants can submit names, email addresses, phone numbers, home addresses, and availability, and are required to complete a personality test as part of the job application process.

Once logged in, the researchers submitted a job application to the test franchise to see how the process worked.

During this test, they noticed that HTTP requests were sent to an API endpoint at /api/lead/cem-xhr, which used a parameter lead_id, which in their case was 64,185,742.

The researchers found that by incrementing and decrementing the lead_id parameter, they were able to expose the full chat transcripts, session tokens, and personal data of real job applicants that previously applied on McHire.

This type of flaw is called an IDOR (Insecure Direct Object Reference) vulnerability, which is when an application exposes internal object identifiers, such as record numbers, without verifying whether the user is actually authorized to access the data.

“During a cursory security review of a few hours, we identified two serious issues: the McHire administration interface for restaurant owners accepted the default credentials 123456:123456, and an insecure direct object reference (IDOR) on an internal API allowed us to access any contacts and chats we wanted,” Carroll explained in a writeup about the flaw.

“Together they allowed us and anyone else with a McHire account and access to any inbox to retrieve the personal data of more than 64 million applicants.”

In this case, incrementing or decrementing a lead_id number in a request returned sensitive data belonging to other applicants, as the API failed to check if the user had access to the data.

Exploiting the IDOR bug to see McDonald's job applications
Exploiting the IDOR bug to see McDonald’s job applications

The issue was reported to Paradox.ai and McDonald’s on June 30.

McDonald’s acknowledged the report within an hour, and the default admin credentials were disabled soon after.

“We’re disappointed by this unacceptable vulnerability from a third-party provider, Paradox.ai. As soon as we learned of the issue, we mandated Paradox.ai to remediate the issue immediately, and it was resolved on the same day it was reported to us,” McDonald’s told Wired in a statement about the research.

Paradox deployed a fix to address the IDOR flaw and confirmed that the vulnerability was mitigated. Paradox.ai has since stated that it is conducting a review of its systems to prevent similar big issues from recurring.

Paradox also told BleepingComputer that the information exposed would be any chatbot interaction, such as clicking on a button, even if no personal information was entered.

Update 7/11/25: Added information from Paradox.

Tines Needle

While cloud attacks may be growing more sophisticated, attackers still succeed with surprisingly simple techniques.

Drawing from Wiz’s detections across thousands of organizations, this report reveals 8 key techniques used by cloud-fluent threat actors.

]]>
https://earlybirdsinvest.com/123456-password-exposed-chats-for-64-million-mcdonalds-job-applicants/feed/ 0 47142
New Mac phishing attack causes fake freezes to nab your Apple ID password https://earlybirdsinvest.com/new-mac-phishing-attack-causes-fake-freezes-to-nab-your-apple-id-password/ https://earlybirdsinvest.com/new-mac-phishing-attack-causes-fake-freezes-to-nab-your-apple-id-password/#respond Wed, 19 Mar 2025 22:56:23 +0000 https://earlybirdsinvest.com/new-mac-phishing-attack-causes-fake-freezes-to-nab-your-apple-id-password/

]]>
https://earlybirdsinvest.com/new-mac-phishing-attack-causes-fake-freezes-to-nab-your-apple-id-password/feed/ 0 26103
Ripple co-founder’s $150M hack tied to LastPass password vault breach https://earlybirdsinvest.com/ripple-co-founders-150m-hack-tied-to-lastpass-password-vault-breach/ https://earlybirdsinvest.com/ripple-co-founders-150m-hack-tied-to-lastpass-password-vault-breach/#respond Sat, 08 Mar 2025 08:46:03 +0000 https://earlybirdsinvest.com/ripple-co-founders-150m-hack-tied-to-lastpass-password-vault-breach/

A forfeiture complaint shared by blockchain detective ZachXBT revealed that the $150 million hack suffered by Ripple co-founder Chris Larsen resulted from private keys stored in the password manager LastPass, which was compromised in 2022. 

The complaint details how the attackers accessed Larsen’s cryptocurrency wallets through stolen vault data from LastPass.

LastPass compromise

In December 2022, LastPass suffered two major data breaches, one in August and another in November, which resulted in the theft of encrypted passwords and vault data. 

According to the complaint, Larsen — referred to as Victim 2 — stored private keys in LastPass’ password vault, which also contained secure notes, banking information, and other credentials.

According to Larsen, he destroyed any physical record of the private keys after inputting them in the password vault. A long, unique password secured access to the online password manager, and devices remained logged for up to 30 days.

At least four devices had access to the account containing the private keys, and only Larsen’s family members were aware of the passcode to any of these devices. 

The FBI has been investigating the LastPass breach, and law enforcement agents working on Larsen’s case have spoken with FBI agents regarding the stolen data. 

The investigation suggests that attackers used the compromised vault data to gain unauthorized access to multiple victims’ cryptocurrency accounts, electronic accounts, and other sensitive information.

The hack

Larsen first disclosed the hack on Jan. 31, 2024, stating that unauthorized access had been detected in several of his personal XRP accounts. 

The attackers stole approximately 213 million XRP, valued at $112.5 million at the time. The stolen funds were laundered through crypto exchanges, including Binance, Kraken, OKX, Gate, MEXC, HTX, and HitBTC.

Larsen and his team immediately notified crypto exchanges to freeze affected addresses but did not publicly reveal any further details about the hack.

ZachXBT questioned Larsen’s decision to hide the cause of the theft. He said:

“Only if Chris Larsen had shown basic transparency with sharing their findings for the root cause prior to this or had helped organize a class action against LastPass.”

Mentioned in this article
]]>
https://earlybirdsinvest.com/ripple-co-founders-150m-hack-tied-to-lastpass-password-vault-breach/feed/ 0 23940
US seizes $23 million in crypto stolen via password manager breach https://earlybirdsinvest.com/us-seizes-23-million-in-crypto-stolen-via-password-manager-breach/ https://earlybirdsinvest.com/us-seizes-23-million-in-crypto-stolen-via-password-manager-breach/#respond Sat, 08 Mar 2025 02:16:31 +0000 https://earlybirdsinvest.com/us-seizes-23-million-in-crypto-stolen-via-password-manager-breach/

Cryptocurrency

U.S. authorities have seized over $23 million in cryptocurrency linked to the theft of $150 million from a Ripple crypto wallet in January 2024. Investigators believe hackers who breached LastPass in 2022 were behind the attack.

Despite the threat actors’ efforts, law enforcement agents traced $23,604,815.09 of the stolen digital assets between June 2024 and February 2025 to the following cryptocurrency exchanges: OKX, Payward Interactive, Inc. (dba Kraken), WhiteBIT, AscendEX Technology SRL, Ftrader Ltd (dba FixedFloat), SwapSpace LLC, and Rabbit Finance LLC (dba CoinRabbit).

A forfeiture complaint unsealed by the U.S. Justice Department yesterday and first spotted by crypto fraud investigator ZachXBT reveals that U.S. Secret Service agents who interviewed the victim believe the attackers could have only stolen the cryptocurrency using private keys extracted by cracking the victim’s password vault stolen in a 2022 breach of an online password manager.

They found that the stolen data and passwords stored in several victims’ password manager accounts were used by attackers to access “their electronic accounts and steal information, cryptocurrency, and other data.”

They also discovered no evidence that the victim’s devices were hacked, which points to the decryption of the stolen online password manager data as the only way the attackers could have obtained the keys needed to compromise the victim’s crypto wallet.

“The scale of a theft and rapid dissipation of funds would have required the efforts of multiple malicious actors, and was consistent with the online password manager breaches and attack on other victims whose cryptocurrency was stolen,” the complaint reads.

“For these reasons, law enforcement agents believe the cryptocurrency stolen from Victim was committed by the same attackers who conducted the attack on the online password manager, and cryptocurrency thefts from other similarly situated victims.”

Crypto theft linked to LastPass hacks

While the investigators didn’t name the online password manager, the complaint says that the platform was hit by “two major data breaches” in August 2022 and November 2022.

This timeline aligns with security breaches disclosed by LastPass three years ago when the company said that attackers stole source code and proprietary technical information, as well as customer vault data, after breaching its cloud storage.

Since then, multiple security experts have shared that they believe the LastPass hackers have cracked some of the stolen vault data and used the extracted private keys and credentials in major cryptocurrency heists.

Even though the investigators didn’t identify the victim, the details match the hack and the theft of $150 million in cryptocurrency from Ripple co-founder and executive chairman Chris Larsen, which was disclosed on January 31, 2024.

Larsen hack disclosure

ZachXBT first linked the $23 million in cryptocurrency seized this week and the hack of Larsen’s XRP wallet.

“A forfeiture complaint filed yesterday by US law enforcement revealed the cause for the ~$150M (283M XRP) hack of Ripple co-founder, Chris Larsen’s wallet in Jan 2024 was the result of storing private keys in LastPass (password manager which was hacked in 2022),” he said today in a Telegram message.

A Ripple spokesperson was not immediately available when BleepingComputer reached out for comment earlier today.

Update March 07, 14:40 EST: LastPass sent the following statement after publishing time:

Since we initially disclosed this incident back in 2022, LastPass has worked in close cooperation with multiple representatives from law enforcement. To date, our law enforcement partners have not made us aware of any conclusive evidence that connects any crypto thefts to our incident.

]]>
https://earlybirdsinvest.com/us-seizes-23-million-in-crypto-stolen-via-password-manager-breach/feed/ 0 23892