AI hiring chatbot breach exposes alarming privacy violations and hiring concerns in fast food industry
"Hackers Break into AI Hiring Chatbot, Could Hire and Reject Fast Food Applicants" 11 January 2024
A group of hackers gained access to the backend of an AI chatbot that fast food franchises use to help automate hiring. The researchers were seemingly able to accept or reject specific job applicants, and had access to a wealth of sensitive information on applicants, the fast food franchises, and the AI company itself, called Chattr...
...Chattr advertises itself as “the first ever automated end-to-end hiring software for the hourly workforce powered by an AI digital assistant.”..
...The researchers [including 'MrBruh'] took [a Firebase configuration of KFC] and put it into Firepwn, a tool available on Github used for testing the security of apps using Firebase. At first, the researchers didn’t have the ability to read any of the data stored. But after creating a new user account through Firebase, they gained read and write access to the underlying database.
This revealed a wealth of data, including names, phone numbers, email addresses, location of branches, messages, work shifts, and some passwords, according to MrBruh’s blog post. The data related to franchisee managers, job applicants, and employees of Chattr...
...But the data exposure was not limited to a single set of KFC data. The researchers found they were able to access an administrator dashboard, revealing a list of organizations using Chattr and granting the ability to accept or deny job applicants, as well as refund payments made to Chattr, MrBruh writes...
...Chattr did not respond to a request for comment from 404 Media.
KFC told 404 Media in an email that Chattr only works with one KFC franchisee. “Chattr is not a vendor affiliated with KFC Corporation. They work with one franchisee only and we are not privy to any details of that arrangement,” the spokesperson wrote...