Close Menu
Global News HQ
    What's Hot

    Gizelle Bryant Shares an Update on the “Emotional” Legal Battle Over Her Father’s Will | Bravo

    November 17, 2025

    Home Depot’s Early Black Friday Sale Includes Free DeWalt Power Tools

    November 17, 2025

    Client Challenge

    November 17, 2025
    Recent Posts
    • Gizelle Bryant Shares an Update on the “Emotional” Legal Battle Over Her Father’s Will | Bravo
    • Home Depot’s Early Black Friday Sale Includes Free DeWalt Power Tools
    • Client Challenge
    • Bitcoin briefly erases 2025 gains as crypto bleeds over weekend
    • ‘What does Harvard see coming?’ asks macro analyst as university ups IBIT position by 257%
    Facebook X (Twitter) Instagram YouTube TikTok
    Trending
    • Gizelle Bryant Shares an Update on the “Emotional” Legal Battle Over Her Father’s Will | Bravo
    • Home Depot’s Early Black Friday Sale Includes Free DeWalt Power Tools
    • Client Challenge
    • Bitcoin briefly erases 2025 gains as crypto bleeds over weekend
    • ‘What does Harvard see coming?’ asks macro analyst as university ups IBIT position by 257%
    • I Hunt Bargains for a Living, and These 12 Early Black Friday Deals Are Going in My Cart
    • A Legendary Vintner’s Crucial Contribution to Auction Napa Valley
    • Get one year of Headspace for only $35 in this Black Friday deal
    Global News HQ
    • Technology & Gadgets
    • Travel & Tourism (Luxury)
    • Health & Wellness (Specialized)
    • Home Improvement & Remodeling
    • Luxury Goods & Services
    • Home
    • Finance & Investment
    • Insurance
    • Legal
    • Real Estate
    • More
      • Cryptocurrency & Blockchain
      • E-commerce & Retail
      • Business & Entrepreneurship
      • Automotive (Car Deals & Maintenance)
    Global News HQ
    Home - Technology & Gadgets - Burger King hacked, systems described as ‘solid as a paper Whopper wrapper in the rain’ – hackers ‘impressed by the commitment to terrible security practices,’ also exploited other RBI brands like Tim Hortons and Popeyes
    Technology & Gadgets

    Burger King hacked, systems described as ‘solid as a paper Whopper wrapper in the rain’ – hackers ‘impressed by the commitment to terrible security practices,’ also exploited other RBI brands like Tim Hortons and Popeyes

    Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp VKontakte Email
    Burger King hacked, systems described as ‘solid as a paper Whopper wrapper in the rain’ – hackers ‘impressed by the commitment to terrible security practices,’ also exploited other RBI brands like Tim Hortons and Popeyes
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Ethical hackers BobDaHacker and BobTheShoplifter have detailed their claim that they uncovered “catastrophic” vulnerabilities in multiple platforms hosted by Restaurant Brands International (RBI). While RBI may not be a very familiar name, this lax security means that systems powering mega brands like Burger King, Tim Hortons, and Popeyes, with over 30,000 locations worldwide, and all were almost trivially easy to hack. “Their security was about as solid as a paper Whopper wrapper in the rain,” snarks the BobDaHacker blog, sharing the full technical exposé (the blog has since been taken down, but it’s archived here).

    (Image credit: BobDaHacker and BobTheShoplifter)

    The vulnerabilities found were a big deal, as we will detail below, including allowing the duo to access employee accounts, ordering systems, and listen to recorded drive-thru conversations, among other exploits. Despite this, the ethical hacking duo that responsibly informed RBI of the flaws were never acknowledged.

    RBI’s vulnerabilities were of whopping proportions

    We mentioned the three big fast food brands in the intro, and the two Bobs found that every one of their assistant platform domains shared the same vulnerabilities. The domains were https://assistant.bk.com, https://assistant.popeyes.com, and https://assistant.timhortons.com, and they could all be easily exploited, across all the group’s 30,000+ locations worldwide. Once in the systems, a hacker could easily:


    You may like

    • View and edit employee accounts
    • Listen to drive-through customer chat recordings
    • Access and control store tablet interfaces
    • Order store equipment like tablets
    • Send notifications to stores
    • And more

    How the vulnerabilities were discovered

    The BobDaHacker blog makes the discovery of the multitude of gaping security holes seem almost trivial. Firstly, it is claimed that the ‘Anyone Can Join This Party’ signup API allowed anyone in, as the web dev team had “forgot to disable user signups.”

    Subsequently, using GraphQL introspection, an “even easier signup endpoint that completely bypassed email verification” was unearthed. The resulting email of the password – in plain text – meant the two Bobs were “impressed by the commitment to terrible security practices.”

    After authentication, the white-hat hackers were able to uncover store employee personal information, internal IDs, configuration details, and more. Furthermore, a GraphQL mutation called createToken allowed the (thankfully) ethical due to “promote ourselves to admin status across the entire platform.”

    Password hard coded in the HTML

    RBI’s catalog of security errors didn’t end there. A quick detour to RBI’s equipment ordering website earned the prize of discovering a self-install device ordering system where the password was hard coded into the HTML.

    Get Tom’s Hardware’s best news and in-depth reviews, straight to your inbox.

    A similar security gaffe was found in the drive-through tablet interfaces in outlets. They had password protection, but the two Bobs show this was also hard coded as ‘admin’ – who’d’ve guessed that?

    password is admin, really

    (Image credit: BobDaHacker and BobTheShoplifter)

    Adding another teetering cherry to this deliciously vulnerable cake, the ethical hackers discovered they could access the full raw audio files of people ordering food at the outlet drive-throughs. Sometimes that audio included personally identifiable information. Interestingly, RBI feeds these recordings to AI-based systems to weigh customer and employee metrics.

    It didn’t end there, as the hackers found the code for the restaurant chains’ bathroom rating screens. It apparently crossed their minds to “give a 5-star review to a bathroom in Tokyo while sitting in your pajamas in Ohio,” but as staunchly white-hat operatives, that, of course, didn’t happen.

    Last but not least, the BobDaHacker blog insists that “no customer data was retained during this research,” with responsible disclosure protocols followed throughout the process. However, we wonder whether these recent experiences influenced their parting shot, which cheekily asserts that “Wendy’s is better.”

    Follow Tom’s Hardware on Google News, or add us as a preferred source, to get our up-to-date news, analysis, and reviews in your feeds. Make sure to click the Follow button!



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Email
    Previous ArticleClient Challenge
    Next Article 3 Things A Nutritionist Wants You To Stop Putting In Your Coffee

    Related Posts

    Get one year of Headspace for only $35 in this Black Friday deal

    November 17, 2025

    You Can Now Add Your Passport to Your iPhone in Apple Wallet. Here's How

    November 17, 2025

    The best gifts for dads that have everything (but deserve more)

    November 16, 2025

    I Made My Kids Build Robots and Read Books to Test the Best Subscription Boxes for Kids

    November 16, 2025
    Leave A Reply Cancel Reply

    ads
    Don't Miss
    Real Estate
    4 Mins Read

    Gizelle Bryant Shares an Update on the “Emotional” Legal Battle Over Her Father’s Will | Bravo

    Two years later, The Real Housewives of Potomac’s Gizelle Bryant is one step closer to getting…

    Home Depot’s Early Black Friday Sale Includes Free DeWalt Power Tools

    November 17, 2025

    Client Challenge

    November 17, 2025

    Bitcoin briefly erases 2025 gains as crypto bleeds over weekend

    November 17, 2025
    Top
    Real Estate
    4 Mins Read

    Gizelle Bryant Shares an Update on the “Emotional” Legal Battle Over Her Father’s Will | Bravo

    Two years later, The Real Housewives of Potomac’s Gizelle Bryant is one step closer to getting…

    Home Depot’s Early Black Friday Sale Includes Free DeWalt Power Tools

    November 17, 2025

    Client Challenge

    November 17, 2025
    Our Picks
    Real Estate
    4 Mins Read

    Gizelle Bryant Shares an Update on the “Emotional” Legal Battle Over Her Father’s Will | Bravo

    Two years later, The Real Housewives of Potomac’s Gizelle Bryant is one step closer to getting…

    Home Improvement & Remodeling
    3 Mins Read

    Home Depot’s Early Black Friday Sale Includes Free DeWalt Power Tools

    We may earn revenue from the products available on this page and participate in affiliate…

    Pages
    • About Us
    • Contact Us
    • Disclaimer
    • Homepage
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube TikTok
    • Home
    © 2025 Global News HQ .

    Type above and press Enter to search. Press Esc to cancel.

    Go to mobile version