HIGH SEVERITYFood

McDonalds Data Breach

McDonald's Fast Food Chain Breach (Salesforce, 2025): 12 Million Customer Email & Home Address Records Exposed

Global fast food restaurant chain.

Verified by ObscureIQ Intelligence

7.0Severity
12.2MRecords
3Fields
2025Year

ObscureIQ Breach Intelligence Scores
4.0
Breach Risk Index
10
Data Value
40
Market Recency
206
days
Since Breach

Risk Interpretation

Primary risks include phishing, loyalty abuse, order fraud, and account takeover. High brand familiarity makes impersonation scams especially effective.

🎯 Impact & Downstream Threats

McDonald's was among the approximately 39 organizations listed on the Scattered LAPSUS$ Hunters dark web leak site in October 2025, with customer contact data including email addresses, phone numbers, and home addresses published as part of the campaign. The company has not made detailed public statements about its specific response to or scope of exposure in this campaign. Salesforce attributed the campaign to customer-side integration vulnerabilities rather than a compromise of its core platfo

Primary downstream threats:
  • SIM swap attacks where phone numbers are present
  • Targeted phishing campaigns using exposed email addresses
  • Doxxing risk from physical address exposure

🔓 Threat Vectors

Phishing, credential stuffing & account takeover
SIM swapping, vishing & SMS phishing
Physical stalking, mail fraud & identity verification
Home targeting, stalking & physical threat

📋 Breach Intelligence

EntityMcDonalds (McDonald's)
OrganizationPublic Company • USA / Global
Breach Date2025-10-10
DBC Added2025-10-03
Added Date2025-10-03
Records~12.2M (12,179,869 records)
Attack VectorUnknown
Threat ActorScattered Lapsus$ Hunters
Data SubjectsCustomer: Direct
Breach PathwaySupply_Chain:Platform
Supply ChainSalesforce
SourceDataBreach.com / ObscureIQ
SensitivityStandard
Breach ID867.0
StatusConfirmed

📝 Executive Summary

McDonald's customer data was exposed in a supply chain breach tied to the customer relationship management platform Salesforce. A threat group calling itself "Scattered LAPSUS$ Hunters" claimed responsibility and released a sample of the stolen database on October 3, 2025, announcing that the full dataset would follow on October 10. McDonald's was one of approximately 39 organizations listed on the group's dark web leak site. Salesforce attributed the compromise to vulnerabilities in customer-side integrations rather than its core platform. The breach affected 12.2 million records. The exposed data includes full names, email addresses, home and alternate phone numbers, and complete mailing addresses. Loyalty contact numbers linked to McDonald's rewards accounts were also present in the sample. This combination of contact and account data creates multiple avenues for abuse. Affected customers face elevated risk of phishing attempts, loyalty point theft, order fraud, and account takeover. McDonald's high brand recognition makes it particularly easy for attackers to craft convincing impersonation scams targeting these individuals. McDonald's has not issued detailed public statements about the scope of its exposure or its specific response to this incident. No regulatory actions or breach notifications have been publicly confirmed. Affected customers should treat any unsolicited contact referencing McDonald's with suspicion, monitor their loyalty accounts for unauthorized activity, and be alert to phishing emails or texts that use their personal details to appear legitimate.

🏢 About McDonalds

McDonald's is the world's largest fast food restaurant chain by revenue and locations, operating more than 40,000 restaurants in over 100 countries through a franchise-heavy model. The company is headquartered in Chicago and publicly traded on the NYSE. Its business spans company-operated restaurants, franchisee licensing, supply chain, and a growing digital and loyalty platform.

Company | Fast food restaurant services | Franchise restaurant chain | Global
Public CompanyUSA / Globalmcdonalds.com

🗂 Why They Hold Your Data

Global restaurant chains collect customer account data, loyalty records, contact details, order history, payment-adjacent information, and delivery activity across digital ordering systems.

📰 Recent Developments

McDonald's has been investing significantly in its digital ordering and loyalty program infrastructure, with the MyMcDonald's Rewards platform accumulating hundreds of millions of registered users globally. The company has navigated menu price sensitivity and consumer pushback over inflation-era pricing. In 2025 it faced simultaneous scrutiny from the Scattered LAPSUS$ Hunters Salesforce campaign and a separate claimed breach of its India operations by the Everest ransomware group.

🔍 Data Points Exposed

3 verified field types:
Email
Phone Number
Home Address

Exposure Categories

LocationPHYS ADDR

Canonical Fields

email_address, phone_number, physical_address:home

🌐 Dark Web Verification

Confirmed
  • Dataset containing ~12.2M records identified in breach intelligence sources
  • Data indexed and searchable across breach notification platforms
  • Source: mcdonalds-salesforce-2025

🛡 Recommended Actions

⚠️ Do not assume this is low sensitivity.

1Freeze Your Credit
Place a credit freeze with Equifax, Experian, and TransUnion.
2Expect Targeted Phishing
Watch for emails referencing this breach. Verify through official channels.
3Enable MFA Everywhere
Enable multi-factor authentication on all accounts.
4Monitor Accounts
Watch for unauthorized activity on financial and personal accounts.
5Check Your Exposure
ObscureIQ clients: this breach is indexed in your profile.

Protect Yourself

Check If You’re Affected

Enter your email to check if your data appears in this breach.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed.

High-Risk? Get an Exposure Audit

Full-spectrum exposure audits for executives and public figures.

Request Consultation

ObscureIQ Advisory

We combine proprietary dark web access with commercial and restricted breach intelligence to verify exposure and assess real-world risk.

If you are:
  • A public-facing individual
  • A high-profile executive
  • A customer of McDonalds
  • Or concerned about credential reuse
Services
AuditsWipesThreat MonitoringTraining

Classification Tags

FoodEmailPhoneAddress

Powered by the ObscureIQ Breach Intelligence Database

© 2026 ObscureIQ · All Rights Reserved · Data Licensing

Latest from ObscureIQ

Credit

What Is Credit Monitoring? And Do I Want It? (Answer: Not Really)

July 14, 2025
Every time there’s a major data breach, companies scramble to offer “free” credit monitoring. It sounds like a responsible move.…
breach economycredit freezecredit scoreequifaxexperian
Credible Threats

Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars.

September 2, 2025
Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars. Over 80% of security incidents now start in the browser. Chrome.…
brave browserbreachesbrowser exploitbrowserschrome
Analysis

Sextortion Spam

May 10, 2025
Sextortion scams aren’t new, but they remain one of the most effective forms of cyber-enabled fraud. These scams don’t rely…
bitcoindeadlinefeargoogle maps apiransom