McDonald’s Indonesia has secured an exposed database after researchers discovered more than 40 million records accessible online, including millions containing customer information.
The data was stored in a MongoDB database associated with the company’s Customer Data Platform. Rather than resulting from a confirmed cyberattack, the incident involved a database that had been left publicly accessible, potentially allowing outsiders to view information without the normal protections expected around customer records.
Approximately 28 million entries were related to customers. Researchers counted around 12.6 million records containing email addresses, 12.5 million containing full names, and roughly one million containing phone numbers. More than 28 million entries also included last-known device identifiers.
Those figures represent database records rather than 28 million confirmed individual victims. A single customer can appear in several records or collections, meaning the available information does not establish exactly how many unique people were affected.
The database contained considerably more than basic contact details. Researchers found more than 12 million consent-related records containing information such as user identifiers, privacy consent settings, and timestamps showing when those preferences were recorded.
McDonald’s loyalty program information was also exposed. More than 226,000 records across several database collections contained loyalty-related information, including unique user identifiers, point transaction IDs, transaction types, and timestamps.
Corporate and operational information appeared alongside customer data. Researchers identified more than 71,000 advertising campaign records containing campaign details and interaction information, as well as approximately 37,800 sales records. Information concerning McDonald’s Indonesia locations and push notifications was also present.
The combination of these datasets could make exposed customers attractive targets for convincing phishing and impersonation attempts. Someone with access to a person’s name, email address, phone number, and information about interactions with McDonald’s could potentially construct a scam that appears more credible than a generic phishing email.
Loyalty information introduces another possible risk because criminals could attempt to impersonate customers or abuse loyalty accounts. Device identifiers and consent records could also provide additional context that helps make fraudulent communications appear connected to a legitimate account or previous activity.
However, there is currently no evidence that criminals accessed or exploited the exposed database. The discovery of an internet-accessible database demonstrates that the information could have been reached, but it does not establish that malicious actors actually downloaded it.
McDonald’s Indonesia closed access to the database after being alerted to the exposure. At the time the incident was disclosed, the company had not provided a public explanation detailing how long the database had been accessible or exactly how many individual customers were affected.
Those unanswered questions remain important because the number of exposed records cannot be directly converted into a victim count. Until further details emerge, the confirmed issue is that a McDonald’s Indonesia customer data system exposed more than 40 million records, with approximately 28 million entries containing customer-related information.