Close Menu
Global News HQ
    What's Hot

    I Hunt Bargains for a Living, and These 12 Early Black Friday Deals Are Going in My Cart

    November 17, 2025

    You Can Now Add Your Passport to Your iPhone in Apple Wallet. Here's How

    November 17, 2025

    Cardano wallet activates after 5 years, loses $6 million in disastrous ADA-to-USDA swap

    November 17, 2025
    Recent Posts
    • I Hunt Bargains for a Living, and These 12 Early Black Friday Deals Are Going in My Cart
    • You Can Now Add Your Passport to Your iPhone in Apple Wallet. Here's How
    • Cardano wallet activates after 5 years, loses $6 million in disastrous ADA-to-USDA swap
    • Entrepreneurs Can Save Hours Every Week With This All-in-One AI Platform
    • abrdn Healthcare Investors Q3 2025 Commentary
    Facebook X (Twitter) Instagram YouTube TikTok
    Trending
    • I Hunt Bargains for a Living, and These 12 Early Black Friday Deals Are Going in My Cart
    • You Can Now Add Your Passport to Your iPhone in Apple Wallet. Here's How
    • Cardano wallet activates after 5 years, loses $6 million in disastrous ADA-to-USDA swap
    • Entrepreneurs Can Save Hours Every Week With This All-in-One AI Platform
    • abrdn Healthcare Investors Q3 2025 Commentary
    • The best gifts for dads that have everything (but deserve more)
    • What Is Selenium And How Can You Tell If You’re Deficient?
    • What Is a Franchising Franchisor and How Do They Operate?
    Global News HQ
    • Technology & Gadgets
    • Travel & Tourism (Luxury)
    • Health & Wellness (Specialized)
    • Home Improvement & Remodeling
    • Luxury Goods & Services
    • Home
    • Finance & Investment
    • Insurance
    • Legal
    • Real Estate
    • More
      • Cryptocurrency & Blockchain
      • E-commerce & Retail
      • Business & Entrepreneurship
      • Automotive (Car Deals & Maintenance)
    Global News HQ
    Home - Technology & Gadgets - Burger King hacked, systems described as ‘solid as a paper Whopper wrapper in the rain’ – hackers ‘impressed by the commitment to terrible security practices,’ also exploited other RBI brands like Tim Hortons and Popeyes
    Technology & Gadgets

    Burger King hacked, systems described as ‘solid as a paper Whopper wrapper in the rain’ – hackers ‘impressed by the commitment to terrible security practices,’ also exploited other RBI brands like Tim Hortons and Popeyes

    Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp VKontakte Email
    Burger King hacked, systems described as ‘solid as a paper Whopper wrapper in the rain’ – hackers ‘impressed by the commitment to terrible security practices,’ also exploited other RBI brands like Tim Hortons and Popeyes
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Ethical hackers BobDaHacker and BobTheShoplifter have detailed their claim that they uncovered “catastrophic” vulnerabilities in multiple platforms hosted by Restaurant Brands International (RBI). While RBI may not be a very familiar name, this lax security means that systems powering mega brands like Burger King, Tim Hortons, and Popeyes, with over 30,000 locations worldwide, and all were almost trivially easy to hack. “Their security was about as solid as a paper Whopper wrapper in the rain,” snarks the BobDaHacker blog, sharing the full technical exposé (the blog has since been taken down, but it’s archived here).

    (Image credit: BobDaHacker and BobTheShoplifter)

    The vulnerabilities found were a big deal, as we will detail below, including allowing the duo to access employee accounts, ordering systems, and listen to recorded drive-thru conversations, among other exploits. Despite this, the ethical hacking duo that responsibly informed RBI of the flaws were never acknowledged.

    RBI’s vulnerabilities were of whopping proportions

    We mentioned the three big fast food brands in the intro, and the two Bobs found that every one of their assistant platform domains shared the same vulnerabilities. The domains were https://assistant.bk.com, https://assistant.popeyes.com, and https://assistant.timhortons.com, and they could all be easily exploited, across all the group’s 30,000+ locations worldwide. Once in the systems, a hacker could easily:


    You may like

    • View and edit employee accounts
    • Listen to drive-through customer chat recordings
    • Access and control store tablet interfaces
    • Order store equipment like tablets
    • Send notifications to stores
    • And more

    How the vulnerabilities were discovered

    The BobDaHacker blog makes the discovery of the multitude of gaping security holes seem almost trivial. Firstly, it is claimed that the ‘Anyone Can Join This Party’ signup API allowed anyone in, as the web dev team had “forgot to disable user signups.”

    Subsequently, using GraphQL introspection, an “even easier signup endpoint that completely bypassed email verification” was unearthed. The resulting email of the password – in plain text – meant the two Bobs were “impressed by the commitment to terrible security practices.”

    After authentication, the white-hat hackers were able to uncover store employee personal information, internal IDs, configuration details, and more. Furthermore, a GraphQL mutation called createToken allowed the (thankfully) ethical due to “promote ourselves to admin status across the entire platform.”

    Password hard coded in the HTML

    RBI’s catalog of security errors didn’t end there. A quick detour to RBI’s equipment ordering website earned the prize of discovering a self-install device ordering system where the password was hard coded into the HTML.

    Get Tom’s Hardware’s best news and in-depth reviews, straight to your inbox.

    A similar security gaffe was found in the drive-through tablet interfaces in outlets. They had password protection, but the two Bobs show this was also hard coded as ‘admin’ – who’d’ve guessed that?

    password is admin, really

    (Image credit: BobDaHacker and BobTheShoplifter)

    Adding another teetering cherry to this deliciously vulnerable cake, the ethical hackers discovered they could access the full raw audio files of people ordering food at the outlet drive-throughs. Sometimes that audio included personally identifiable information. Interestingly, RBI feeds these recordings to AI-based systems to weigh customer and employee metrics.

    It didn’t end there, as the hackers found the code for the restaurant chains’ bathroom rating screens. It apparently crossed their minds to “give a 5-star review to a bathroom in Tokyo while sitting in your pajamas in Ohio,” but as staunchly white-hat operatives, that, of course, didn’t happen.

    Last but not least, the BobDaHacker blog insists that “no customer data was retained during this research,” with responsible disclosure protocols followed throughout the process. However, we wonder whether these recent experiences influenced their parting shot, which cheekily asserts that “Wendy’s is better.”

    Follow Tom’s Hardware on Google News, or add us as a preferred source, to get our up-to-date news, analysis, and reviews in your feeds. Make sure to click the Follow button!



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Email
    Previous ArticleClient Challenge
    Next Article 3 Things A Nutritionist Wants You To Stop Putting In Your Coffee

    Related Posts

    You Can Now Add Your Passport to Your iPhone in Apple Wallet. Here's How

    November 17, 2025

    The best gifts for dads that have everything (but deserve more)

    November 16, 2025

    I Made My Kids Build Robots and Read Books to Test the Best Subscription Boxes for Kids

    November 16, 2025

    Moon phase today explained: What the moon will look like on November 16, 2025

    November 16, 2025
    Leave A Reply Cancel Reply

    ads
    Don't Miss
    Home Improvement & Remodeling
    6 Mins Read

    I Hunt Bargains for a Living, and These 12 Early Black Friday Deals Are Going in My Cart

    As someone who often writes about deals and discounts, I’m excited to report that Amazon…

    You Can Now Add Your Passport to Your iPhone in Apple Wallet. Here's How

    November 17, 2025

    Cardano wallet activates after 5 years, loses $6 million in disastrous ADA-to-USDA swap

    November 17, 2025

    Entrepreneurs Can Save Hours Every Week With This All-in-One AI Platform

    November 16, 2025
    Top
    Home Improvement & Remodeling
    6 Mins Read

    I Hunt Bargains for a Living, and These 12 Early Black Friday Deals Are Going in My Cart

    As someone who often writes about deals and discounts, I’m excited to report that Amazon…

    You Can Now Add Your Passport to Your iPhone in Apple Wallet. Here's How

    November 17, 2025

    Cardano wallet activates after 5 years, loses $6 million in disastrous ADA-to-USDA swap

    November 17, 2025
    Our Picks
    Home Improvement & Remodeling
    6 Mins Read

    I Hunt Bargains for a Living, and These 12 Early Black Friday Deals Are Going in My Cart

    As someone who often writes about deals and discounts, I’m excited to report that Amazon…

    Technology & Gadgets
    2 Mins Read

    You Can Now Add Your Passport to Your iPhone in Apple Wallet. Here's How

    iPhone users can now add their passport to Apple Wallet to get through TSA checkpoints…

    Pages
    • About Us
    • Contact Us
    • Disclaimer
    • Homepage
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube TikTok
    • Home
    © 2025 Global News HQ .

    Type above and press Enter to search. Press Esc to cancel.

    Go to mobile version