Burger King Serves Up Sensitive Data, No MayoBurger King Serves Up Sensitive Data, No Mayo
The incident marks the second time since 2019 that a misconfiguration could have let threat actors "have it their way" when it comes to BK's data.
![agitated man wearing burger king crown agitated man wearing burger king crown](https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt7af168a8b84e0dde/64f17d7ca01b5a7460517b6e/burger_king_Neville_Styles_Alamy.jpg?width=1280&auto=webp&quality=95&format=jpg&disable=upscale)
A misconfiguration in the site for Burger King France has exposed sensitive data that could have been used to launch a whopper of a cyberattack against the chain.
Researchers at Cybernews found the flaw and noted that a similar 2019 misconfiguration had leaked information on kids who bought Burger King menus.
The most recent Burger King data leak incident exposed database credentials, and what researchers think are job posts and applicant data. The analysts weren't legally able to view the contents of the database, the report noted.
By combining the compromised credentials with the site's Google Tag Manager ID, threat actors could have changed the Tag ID to a container they control, and from there execute arbitrary code, the Security Affairs team explained. The researchers also discovered a Google Analytics ID among the exposed data, which could have been used to manipulate the site's analytics.
The researchers alerted Burger King to the potential for cyberattacks stemming from the data exposure, and the problem has been fixed.
About the Author
You May Also Like
Uncovering Threats to Your Mainframe & How to Keep Host Access Secure
Feb 13, 2025Securing the Remote Workforce
Feb 20, 2025Emerging Technologies and Their Impact on CISO Strategies
Feb 25, 2025How CISOs Navigate the Regulatory and Compliance Maze
Feb 26, 2025Where Does Outsourcing Make Sense for Your Organization?
Feb 27, 2025