Bugs in a major McDonald’s India delivery system exposed sensitive customer data

A major McDonald’s delivery system in India exposed the personal information of its customers and drivers due to several simple security flaws, TechCrunch has exclusively learned.

The flaws, discovered by Traceable AI security researcher Eaton Zveare, were found in the APIs of the delivery system associated with McDonald’s India (West & South), which is owned by Hardcastle Restaurants.

Zveare exclusively told TechCrunch that bugs in the company’s delivery system, McDelivery, meant anyone could access, hijack, redirect, or real-time track orders, or make legitimate orders for $0.01, by interacting with the company’s API, which apps and websites use for placing orders and tracking. This is because the API wasn’t properly checking to make sure the person making requests was allowed to make requests. The bugs also allowed access to invoices and provided the ability to submit feedback for customer orders.

The security flaws exposed McDelivery customer full names, email addresses, and phone numbers of McDonald’s India (West & South) customers, and exposed access to vehicle numbers, profile pictures, and tracked the real-time location of the restaurant chain’s drivers delivering orders.

In a since-published blog post, Zveare found the vulnerabilities and reported them to the restaurant chain in July. They were fixed in late September, per the researcher.

McDonald’s India told TechCrunch that a “thorough verification of systems and logs” showed the flaws did not result in a breach of its customer data.

“We conduct regular audits and assessments to continuously strengthen our security measures, and have all the necessary enhancements implemented, ensuring all our systems are up to date and secure,” Sulakshna Mukherjee, a spokesperson at McDonald’s India (West & South), said in a statement emailed to TechCrunch.

McDonald’s India did not disclose the number of customers whose information may have been exposed by the bugs. However, the researcher told TechCrunch that the flaws exposed access to hundreds of millions of orders.

“The McDelivery (West & South) mobile app uses the same exact back-end APIs as the website. As a result, both were vulnerable to the same exploits,” the researcher told TechCrunch.

This is not the first time McDonald’s India has exploited its customers’ sensitive data. In 2017, the delivery app of McDonald’s India (West & South) leaked the personal information of about 2.2 million customers.

Jagmeet covers startups, tech policy-related updates, and all other major tech-centric developments from India for TechCrunch. He previously worked as a principal correspondent at NDTV. You can reach out to him at mail[at]journalistjagmeet[dot]com.

View Bio

Read More

Latest

Franklin Templeton says Wall Street fears blockchain because it threatens its profits

Jenny Johnson, Franklin Templeton's CEO, said blockchain and crypto threaten a huge number of business models that exist today in traditional finance. Jun 3, 2026, 7:04 a.m. 2 min read Make preferred on The future of asset management is shifting on-chain, but the transition is exposing a major structural conflict over traditional corporate revenue. Speaking

Big tech is ‘terrified’ of AI agents wiping out ad revenue, says Billions Network CEO

Evin McMullen’s view on AI agents disrupting Google’s and Facebook’s business model was previously shared by Cardano Founder Charles Hoskinson and Cloudflare CSO Stephanie Cohen. Jun 3, 2026, 6:51 a.m. 2 min read Make preferred on The legacy financial and digital frameworks propping up the current internet architecture face an imminent, existential crisis. Evin McMullen

What Responsibilities Come With Sole Proprietorship for Self-Employed Individuals?

As a sole proprietor, you take on significant responsibilities that impact your business and personal finances. You’ll need to maintain precise financial records, file taxes using Schedule C, and guarantee compliance with local regulations. Moreover, you’re personally liable for any business debts, which underscores the importance of liability insurance. Securing the right licenses and permits

Philippine Blockchain Week 2026 marks shift from Web3 potential to real-world deployment

Homepage > News > Business > Philippine Blockchain Week 2026 marks shift from Web3 potential to real-world deployment MANILA, Philippines — The next phase of the digital economy will not be announced after the fact—it will take shape in real time at Philippine Blockchain Week (PBW) 2026. From June 19 to 21 at the SMX

Newsletter

Don't miss

Franklin Templeton says Wall Street fears blockchain because it threatens its profits

Jenny Johnson, Franklin Templeton's CEO, said blockchain and crypto threaten a huge number of business models that exist today in traditional finance. Jun 3, 2026, 7:04 a.m. 2 min read Make preferred on The future of asset management is shifting on-chain, but the transition is exposing a major structural conflict over traditional corporate revenue. Speaking

Big tech is ‘terrified’ of AI agents wiping out ad revenue, says Billions Network CEO

Evin McMullen’s view on AI agents disrupting Google’s and Facebook’s business model was previously shared by Cardano Founder Charles Hoskinson and Cloudflare CSO Stephanie Cohen. Jun 3, 2026, 6:51 a.m. 2 min read Make preferred on The legacy financial and digital frameworks propping up the current internet architecture face an imminent, existential crisis. Evin McMullen

What Responsibilities Come With Sole Proprietorship for Self-Employed Individuals?

As a sole proprietor, you take on significant responsibilities that impact your business and personal finances. You’ll need to maintain precise financial records, file taxes using Schedule C, and guarantee compliance with local regulations. Moreover, you’re personally liable for any business debts, which underscores the importance of liability insurance. Securing the right licenses and permits

Philippine Blockchain Week 2026 marks shift from Web3 potential to real-world deployment

Homepage > News > Business > Philippine Blockchain Week 2026 marks shift from Web3 potential to real-world deployment MANILA, Philippines — The next phase of the digital economy will not be announced after the fact—it will take shape in real time at Philippine Blockchain Week (PBW) 2026. From June 19 to 21 at the SMX

Top 7 Cloud Accounting Software Options for Small Businesses

If you’re a small business owner, choosing the right cloud accounting software can greatly impact your financial management. There are several top contenders available, each with distinct features that cater to various needs and budgets. QuickBooks Online stands out for its user-friendly interface, whereas Wave offers a free option for solo entrepreneurs. As you evaluate

Jury acquits 2 business executives of bribing Navy admiral for government contract

A federal jury has acquitted two business executives of charges that they conspired to bribe a retired four-star U.S. Navy admiral, who is now serving a six-year prison sentence for his conviction on corruption charges By MICHAEL KUNZELMAN Associated Press WASHINGTON -- A federal jury has acquitted two business executives of charges that they conspired

US Business Leaders Optimistic About China Cooperation, Emphasize Importance of Chinese Market

© 2026 China Money Network. All Rights Reserved. Disclaimer: The views, opinions, forecasts, and statements made by our hosts and guests are the personal views of those respective individuals and may or may not be either endorsed or accepted by China Money Network Limited or the companies with which these individuals are employed.

Tesla’s Business Has Become Much More Diversified in Just the Past Five Years. Does That Make Its Stock a Better Buy Today?

Key Points Tesla's energy generation and storage segment generated 27% revenue growth last year. The company's non-automotive segments were able to help offset a double-digit decline in auto revenue in 2025. These 10 stocks could mint the next wave of millionaires › Tesla (NASDAQ: TSLA) is known for its electric vehicles (EVs), and while they