Sponsored By

Hackers steal data from McDonald’s in U.S., South Korea and TaiwanHackers steal data from McDonald’s in U.S., South Korea and Taiwan

Company says breach affected no U.S. consumer information, but some employees and franchisees risk phishing attack

Ron Ruggless, Senior Editor

June 11, 2021

3 Min Read
Nation's Restaurant News logo in a gray background | Nation's Restaurant News

McDonald’s Corp. data was breached by hackers in some markets, including the United States, South Korea and Taiwan, and the company warned employees and franchisees to be on the alert for phishing attacks, the company said Friday.

The Chicago-based quick-service chain said it had hired external consultants to investigate unauthorized activity on an internal security system. The investigation was prompted by a breach that was identified about a week after it happened.

“A thorough investigation was conducted, and we worked with experienced third parties to support this investigation,” a McDonald’s spokesperson said Friday.

“While we were able to close off access quickly after identification, our investigation has determined that a small number of files were accessed, some of which contained personal data,” the spokesperson said.

“Based on our investigation, only Korea and Taiwan had customer personal data accessed, and they will be taking steps to notify regulators and customers listed in these files,” the company said. “No customer payment information was contained in these files. In the coming days, a few additional markets will take steps to address files that contained employee personal data.”

The company said business was not interrupted.

The breach was first reported Friday by the Wall Street Journal. The report noted that McDonald’s told its U.S. employees “the breach disclosed some business contact information for U.S. employees and franchisees, along with some information about restaurants such as seating capacity and the square footage of play areas.”

“The company said no customer data was breached in the U.S., and that the employee data exposed wasn’t sensitive or personal,” the report noted. “The company advised employees and franchisees to watch for phishing emails and to use discretion when asked for information.”

Ed Bishop, co-founder and chief technology officer at London-based Tessian, an email security company, said in a statement: “Hackers will be quick to exploit the business contact details exposed in this breach, either simply selling the data or using the information to send convincing phishing, smishing or vishing attacks to victims of the breach.” Phishing is via email, smishing is via text message, and vishing is via phone call or voice message.

“The warning for all McDonald's employees and franchisees, then, is to watch out for phishing emails and verify any requests for payments or information with the supposed source via another means of communication before complying with the request,” Bishop said. “No matter how urgent the message appears, always take a minute to check its legitimacy.”

Bishop said McDonald’s notified regulators in Asia of the breach Friday, and that they would contact customers and employees. “The company said its divisions would also notify some employees in South Africa and Russia of possible unauthorized access to their information,” Bishop said.

The breach in South Korea and Taiwan involved customer emails, phone numbers and addresses for delivery customers but it did not include payment information, the Wall Street Journal said.

The McDonald’s spokesperson said the company has “made substantial investments to implement multiple security tools as part of our in-depth cybersecurity defense.

“These tools allowed us to quickly identify and contain recent unauthorized activity on our network,” the company said. “A thorough investigation was conducted, and we worked with experienced third parties to support this investigation.”

McDonald’s USA has 14,000 restaurants, with 95% of them franchised. Globally, the brand has more than 39,000 locations.

Contact Ron Ruggless at [email protected]

Follow him on Twitter: @RonRuggless

Read more about:

McDonald’s

About the Author

Ron Ruggless

Senior Editor, Nation’s Restaurant News / Restaurant Hospitality

Ron Ruggless serves as a senior editor for Informa Connect’s Nation’s Restaurant News (NRN.com) and Restaurant Hospitality (Restaurant-Hospitality.com) online and print platforms. He joined NRN in 1992 after working 10 years in various roles at the Dallas Times Herald newspaper, including restaurant critic, assistant business editor, food editor and lifestyle editor. He also edited several printings of the Zagat Dining Guide for Dallas-Fort Worth, and his articles and photographs have appeared in Food & Wine, Food Network and Self magazines. 

Ron Ruggless’ areas of expertise include foodservice mergers, acquisitions, operations, supply chain, research and development and marketing. 

Ron Ruggless is a frequent moderator and panelist at industry events ranging from the Multi-Unit Foodservice Operators (MUFSO) conference to RestaurantSpaces, the Council of Hospitality and Restaurant Trainers, the National Restaurant Association’s Marketing Executives Group, local restaurant associations and the Horeca Professional Expo in Madrid, Spain.

Ron Ruggless’ experience:

Regional and Senior Editor, Informa Connect’s Nation’s Restaurant News and Restaurant Hospitality (1992 to present)

Features Editor – Dallas Times Herald (1989-1991)

Restaurant Critic and Food Editor – Dallas Times Herald (1987-1988)

Editing Roles – Dallas Times Herald (1982-1987)

Editing Roles – Charlotte (N.C.) Observer (1980-1982)

Editing Roles – Omaha (Neb.) World-Herald (1978-1980)

Email: [email protected]

Social media:

Twitter@RonRuggless

LinkedIn: www.linkedin.com/in/ronruggless

Instagram: @RonRuggless

TikTok: @RonRuggless

 

Subscribe Nation's Restaurant News Newsletters
Get the latest breaking news in the industry, analysis, research, recipes, consumer trends, the latest products and more.