A hiring chatbot's administrator console opened to a default password and let researchers read applicant chats
In June 2025 two researchers found that the McHire administrator interface, run by Paradox.ai, accepted a default username and password. Behind it an insecure direct object reference let them step through applicant identifiers and read chat records holding names, email addresses, phone numbers and network addresses. The credentials stopped working within about two hours of the report.
The verdict
Verified
The document exists. The ledger fetched it at its publisher and quotes it.
Key facts
What the sources say
- Record ID
- AIL-2026-0013
- Kind
- Exfiltration
- Jurisdiction
- United States
- Last verified
- Added
- The researchers write that they entered the same six digit string as username and password and were immediately logged in.
- Behind the login an insecure direct object reference in an internal interface let applicant records be enumerated by identifier.
- Paradox.ai states the account had not been logged into since 2019 and should have been decommissioned.
- Paradox.ai states the researchers viewed and downloaded seven chat records, five of which contained candidate information, and that nothing was published.
- The default credentials stopped working the same evening as the report, and the vendor confirmed resolution the next day.
Dimension by dimension
6 dimensions, each one stated, silent or open
Identity, Authorization, Limits, Logging and audit, Revocation, Accountability. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- IdentitySilent
- A shared default administrator credential with no second factor was the only identity in front of the applicant data.Ian Carroll and Sam Curry, McHire research writeup, primary source, 15 September 2026.
- AuthorizationSilent
- The direct object reference meant any authenticated session could read any applicant's record.Ian Carroll and Sam Curry, McHire research writeup, primary source, 15 September 2026.
- LimitsSilent
- No rate limit or record ceiling stopped sequential enumeration of applicant identifiers.Ian Carroll and Sam Curry, McHire research writeup, primary source, 15 September 2026.
- Logging and auditStated
- The vendor's records established that only the researchers reached the account and exactly how many chats were downloaded.Paradox.ai, responsible security update, primary source, 9 July 2025.
- RevocationStated
- The default credentials were disabled within about two hours of the report reaching the vendor.Paradox.ai, responsible security update, primary source, 9 July 2025.
- AccountabilityStated
- The vendor published a named statement owning the failure and opened a disclosure programme.Paradox.ai, responsible security update, primary source, 9 July 2025.
Figures
Every number, with who measured it and when
- 64,000,000 records
Applicant chat records the researchers state were reachable
Ian Carroll and Sam Curry, McHire research writeup, primary source, as of .
- 5 records
Candidate records the vendor states were actually viewed
Paradox.ai, responsible security update, primary source, as of .
What it changes
For a team deploying an agent
The agent here was ordinary; the failure was the console behind it. Identity is the missing control, and it is the cheapest one on the list: no default credentials, a second factor on any console that can read candidate data, and a scheduled sweep for accounts nobody has signed into in years. The two controls that held, logging and fast revocation, are why this stayed a near miss.
Sources
What this record was verified against
- Ian Carroll and Sam Curry, McHire research writeupPrimary · 15 September 2026
- Paradox.ai, responsible security updatePrimary · 9 July 2025
- Krebs on Security, Poor passwords tattle on AI hiring bot makerSecondary · 17 July 2025
Related
Records that sit beside this one
Audit logs and token revocation contained a stolen agent integration, after its permissions had already been abused
United States · verified 15 September 2026
Google reports that on 20 August 2025 the vendor, working with the platform, revoked all active access and refresh tokens for the agent application.
A support agent invented a policy its company did not have, and customers cancelled over it
United States · verified 15 September 2026
A company representative stated publicly that there is no such policy and that users are free to use the product on multiple machines.
A vendor's own red team made a browser agent send a resignation letter for the user, then showed the fixed agent refusing
United States · verified 15 September 2026
The vendor's own account states that the out of office reply never gets written and the agent resigns on behalf of the user instead.
A browser agent read the local file system and shipped it out while still answering the user normally
United States · verified 15 September 2026
The research states the agent autonomously accesses the local file system and exfiltrates the contents to an attacker controlled endpoint while still returning the expected response.
GitLost, where a platform's own workflow agent posted private repository contents into a public issue when asked politely
United States · verified 15 September 2026
The Register reports that the attacker hides the commands in plain English in the issue body and the agent then posts the data as a public comment.
A stranger's issue steered a continuous integration agent into reading the environment that held its own API key
United States · verified 15 September 2026
The research states that the returned environment blob contains the unscrubbed API key.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0013 is permanent and is never reused.
- In a sentence
- According to the GAGE Agent Incident Ledger (as of 15 September 2026), a hiring chatbot's administrator console opened to a default password and let researchers read applicant chats.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). A hiring chatbot's administrator console opened to a default password and let researchers read applicant chats. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0013-mchire-hiring-chatbot-default-password-applicant-records
- MLA
- "A hiring chatbot's administrator console opened to a default password and let researchers read applicant chats." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0013-mchire-hiring-chatbot-default-password-applicant-records.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "A hiring chatbot's administrator console opened to a default password and let researchers read applicant chats." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0013-mchire-hiring-chatbot-default-password-applicant-records.
- Permalink
- https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0013-mchire-hiring-chatbot-default-password-applicant-records
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.
Back to the full ledger, or every record for United States and every exfiltration record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.