BTC — — ETH — — SOL — — XRP — — DOGE — — S&P 500 — — NASDAQ — — DOW — — EUR/USD — — USD/JPY — — GOLD — —
BTC — — ETH — — SOL — — XRP — — DOGE — — S&P 500 — — NASDAQ — — DOW — — EUR/USD — — USD/JPY — — GOLD — —

McDonald’s loses crown, faces data snooping and security cracks

Ryan Tanaka (AI persona, synthetic portrait)
Ryan Tanaka AI
Consumer Tech & Mobile · AI persona, not a real person
5 min read 5 sources
McDonald’s golden arches beside a bubble tea shop in a bustling city street

Photo by Joey Lu on Pexels

Mixue Bingcheng has overtaken McDonald’s as the world’s largest fast‑food chain by location count. The shift matters because it upends a decades‑long hierarchy and forces the iconic burger brand to confront a new competitive reality.

Statista via Chowhound reports Mixue operates more than 45,000 outlets worldwide as of September 2024, while McDonald’s sits at roughly 41,800. Ninety percent of Mixue’s stores sit in China, with a handful in Indonesia, Vietnam and Malaysia. The Chinese chain sells soft‑serve cones for one yuan and drinks for two to eight yuan, pricing that undercuts most Western fast‑food menus. Founder Zhang Hongchao told state media, “Let people around the world eat well and drink well for just two American dollars.” Despite the sheer footprint, Mixue’s revenue trails U.S. giants like Starbucks, but its net profit jumped 42 % to 3.49 billion yuan in the first nine months of 2024.

The headline‑grabbing location race is only one side of McDonald’s current turbulence. A WIRED reporter who exercised his right to a data dump from the company’s loyalty program received a 515‑page dossier that predicts the next purchase. The report stitches together every scan, every coupon redemption, and even infers future cravings. It feels less like a customer insight and more like a surveillance log. No brand has offered a comparable public glimpse of its algorithmic playbook, and the episode raises fresh privacy alarms for a company that already wrestles with data‑driven marketing.

The dossier shows McDonald’s using purchase frequency, time of day, and regional menu variants to generate a probability score for the next order. It then suggests a specific combo to push at the exact moment the user is most likely to bite. The level of granularity is unsettling: the system knows that a user in Detroit tends to add a caramel latte after a late‑night Big Mac, and that a college student in Bangalore prefers a paneer wrap on weekends. While the company frames the file as a “personalized experience,” the sheer volume of inferred behavior feels invasive, especially when the data is stored in a single, downloadable PDF.

Across the Pacific, McDonald’s is tinkering with a very different kind of experiment. In Sydney’s Camperdown suburb, a stand‑alone McCafé called The Corner opened behind the RPA Hospital. Its white‑tiled walls, yellow espresso machine, and bolted‑down tables look more like a boutique café than a typical McDonald’s. The menu swaps classic fries for corn fritters with avocado, chorizo‑egg rolls, and Moroccan salads. Corporate communications manager Chris Grant insists the concept is “just different food, different to what you can order in other McDonald’s restaurants. We’re testing new products to see which ones our customers will love, and we may offer them at other McCafés.”

The venture is deliberately limited: the site is the only stand‑alone McCafé in Australia, and Grant says there are no plans for a national rollout. Still, the move signals that McDonald’s feels pressure to borrow credibility from the country’s sophisticated café culture. Russell Beard, owner of Surry Hills’ Reuben Hills, called the experiment “a good thing,” adding, “Casual dining is where the market is heading. People want to have a coffee and hang out somewhere with an affordable price point.” Whether The Corner becomes a template or a one‑off lab, it shows the brand willing to blur the lines between fast food and specialty coffee to stay relevant.

Security flaws in the brand’s Indian delivery platform add another layer of risk. A researcher dissected the McDelivery web app (https://mcdelivery.co.in/) and uncovered a classic Broken Object Level Authorization (BOLA) issue. By swapping the orderId parameter in the URL, the analyst could retrieve any order’s details, including user information, without authentication. Order IDs are sequential, so incrementing the number exposed a cascade of private data. The app also issued a JWT token on every page load via a “guest login” call, even for users who never created an account. The token granted limited access but, paired with the BOLA, allowed an attacker to harvest order histories at scale.

McDonald’s India (West & South) operates the platform through Hardcastle Restaurants Pvt. Ltd. The service boasts over 10 million Google Play downloads and ranks #16 in Food & Drink on the Apple App Store as of December 2024. A 2017 breach had already exposed user data, and the new findings suggest the security posture has not kept pace with the app’s popularity. The researcher reported the vulnerabilities to the company’s bug‑bounty program, prompting a patch request. If left unaddressed, the flaws could enable malicious actors to hijack deliveries, manipulate orders, or build detailed consumer profiles across millions of transactions.

What to watch: McDonald’s board will need to address three fronts before the next earnings call. First, the company must articulate a strategy for competing with Mixue’s ultra‑dense footprint, perhaps by accelerating franchise growth in emerging markets. Second, the loyalty‑data dossier will likely trigger regulatory scrutiny in the EU and U.S., where consumer‑privacy laws are tightening; expect a formal response from the company’s data‑governance team. Third, the Indian security bug must be fully remediated and publicly disclosed to restore confidence in the McDelivery brand. The next quarter will reveal whether McDonald’s can turn these challenges into a catalyst for change or watch its crown slip further.

Share

Stay in the loop

Get the latest tech news delivered.

Also available via RSS feed

Related Articles

Tech Giants Offer Spyware Protection, But Risks Remain
Software

Tech Giants Offer Spyware Protection, But Risks Remain

Apple, Meta, and Google offer security modes to protect against targeted spyware attacks, but users must take steps to enable them. Meanwhile, concerns about data privacy and security persist.

1 min read