Skip to content
Unlisted Report logoUnlisted ReportSubscribe
Data Breaches

McDonald's Indonesia leak exposes 28 million customers

An unsecured MongoDB database left 40 million records online, including names, emails, phone numbers and loyalty data of 28 million customers.

By · Published · Updated · 4 min read

Exposed database graphic for the McDonald's Indonesia leak

Researchers at Cybernews found an open database belonging to McDonald's Indonesia that exposed more than 40 million records, about 28 million of them tied to customers.

What was exposed

The database was McDonald's Indonesia's Customer Data Platform, stored in MongoDB with no password protection. It contained:

  • Customer names, email addresses and phone numbers
  • Device IDs
  • Loyalty card data and point transactions
  • Sales information

The database has now been closed.

How criminals use data like this

A leak with no passwords or card numbers can still do real harm:

  • Targeted scams: a fraudster who knows your name, number and that you use the McDonald's app can send a very convincing "your points are expiring" message.
  • Loyalty fraud: point balances and transaction data can be used to drain or resell rewards.
  • Account takeover: emails and phone numbers are the starting point for password-reset and SIM-swap attacks.

Why misconfigured databases keep leaking

This is not a hack in the usual sense — nobody broke in. Cloud databases are often deployed with default settings that leave them open to the internet, and automated scanners find them within hours. Basic controls such as authentication, network restrictions and regular exposure scans would have prevented it.

What customers should do

  • Treat unexpected texts and emails about McDonald's rewards with suspicion; open the app directly instead of clicking links.
  • Change your password if you reuse it elsewhere, and turn on two-factor authentication where offered.

Sources

Read next