Company · Fast food restaurant services · Franchise restaurant chain · Global
Global fast food restaurant chain.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
McDonald's customer data was exposed in a supply chain breach tied to the customer relationship management platform Salesforce. A threat group calling itself "Scattered LAPSUS$ Hunters" claimed responsibility and released a sample of the stolen database on October 3, 2025, announcing that the full dataset would follow on October 10. McDonald's was one of approximately 39 organizations listed on the group's dark web leak site. Salesforce attributed the compromise to vulnerabilities in customer-side integrations rather than its core platform. The breach affected 12.2 million records. The exposed data includes full names, email addresses, home and alternate phone numbers, and complete mailing addresses. Loyalty contact numbers linked to McDonald's rewards accounts were also present in the sample. This combination of contact and account data creates multiple avenues for abuse. Affected customers face elevated risk of phishing attempts, loyalty point theft, order fraud, and account takeover. McDonald's high brand recognition makes it particularly easy for attackers to craft convincing impersonation scams targeting these individuals. McDonald's has not issued detailed public statements about the scope of its exposure or its specific response to this incident. No regulatory actions or breach notifications have been publicly confirmed. Affected customers should treat any unsolicited contact referencing McDonald's with suspicion, monitor their loyalty accounts for unauthorized activity, and be alert to phishing emails or texts that use their personal details to appear legitimate.
Full threat analysis, exploitation vectors, and principal guidance below.
12 additional sections · verified field analysis · defensive doctrine
12.2M records analyzed
McDonald's is the world's largest fast food restaurant chain by revenue and locations, operating more than 40,000 restaurants in over 100 countries through a franchise-heavy model. The company is headquartered in Chicago and publicly traded on the NYSE. Its business spans company-operated restaurants, franchisee licensing, supply chain, and a growing digital and loyalty platform.
Global restaurant chains collect customer account data, loyalty records, contact details, order history, payment-adjacent information, and delivery activity across digital ordering systems.
McDonald's has been investing significantly in its digital ordering and loyalty program infrastructure, with the MyMcDonald's Rewards platform accumulating hundreds of millions of registered users globally. The company has navigated menu price sensitivity and consumer pushback over inflation-era pricing. In 2025 it faced simultaneous scrutiny from the Scattered LAPSUS$ Hunters Salesforce campaign and a separate claimed breach of its India operations by the Everest ransomware group.
McDonald's was among the approximately 39 organizations listed on the Scattered LAPSUS$ Hunters dark web leak site in October 2025, with customer contact data including email addresses, phone numbers, and home addresses published as part of the campaign. The company has not made detailed public statements about its specific response to or scope of exposure in this campaign. Salesforce attributed the campaign to customer-side integration vulnerabilities rather than a compromise of its core platform.
• SIM swap attacks where phone numbers are present | • Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure
A consumer-service breach: contact and account data supports phishing, account takeover and profile enrichment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.
Motivation: Financial, notoriety, extortion
A 2025 claimed fusion of Scattered Spider, LAPSUS$, and ShinyHunters branding. It used Telegram and forum channels for threats, leak theatrics, and extortion pressure.
Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.
Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation