Compromised information includes names, postal and e-mail addresses, phone numbers and age-verification data
By Juan Carlos Perez
IDG News Service (Miami Bureau)

MIAMI (12/11/2010) – McDonald’s is working with law enforcement authorities after malicious hackers broke into another company’s databases and stole information about an undetermined number of the fast food chain’s customers.

McDonald’s has also alerted potentially affected customers via e-mail and through a message on its website.

“We have been informed by one of our long-time business partners, Arc Worldwide, that limited customer information collected in connection with certain McDonald’s websites and promotions was obtained by an unauthorized third party,” a McDonald’s spokeswoman said via e-mail on Saturday.

McDonald’s hired Arc to develop and coordinate the distribution of promotional e-mail messages, and Arc in turn relied on an unidentified e-mail company to manage the customer information database. This e-mail company’s systems were hacked into.

The data, which customers had provided voluntarily, doesn’t include Social Security Numbers, credit card numbers, nor any sensitive financial information, she said.

“Rather, the limited information includes what was required to confirm the customer’s age, methods to contact the customer, and other general preference information,” the spokeswoman added.

This means that customer data likely includes full names, phone numbers, postal addresses and e-mail addresses. The spokeswoman didn’t say what information was required for age confirmation, so it’s not clear if customers simply checked a box saying they were adults or if they had to provide their date of birth.

“In the event that you are contacted by someone claiming to be from McDonald’s asking for personal or financial information, do not respond and instead immediately contact us,” reads the McDonald’s note to customers. The number to call is 1-800-244-6227.

In addition to working with law enforcement agencies, McDonald’s is probing the security breakdown at the company hired by Arc, which is the marketing services division of ad agency Leo Burnett. Arc’s specialities include digital communications, direct marketing, promotions and shopper marketing, according to its website.

The spokeswoman didn’t say how many people are potentially affected and in what countries, besides the U.S. She also didn’t say when the breach happened.

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Looking for something?

Use the form below to search the site:


Still not finding what you're looking for? Drop a comment on a post or contact us so we can take care of it!

Gallery

DSC_8744-1 DSC_3814 DSC06164 copy.jpg DSC_6047 DSC09290 DSC_8503 CSO-Issue1-23.JPG DSC_0684 copy.jpg DSC05556.JPG DSC_2157 copy CSO-NetSol 318 copy.jpg DSC_3386 copy rf copy DSC_7813 DSC_1721 copy DSC_1489 DSC08079 DSC08039 TweetDeck 105 copy DSC_2166 copy DSC_8660 DSC_1462 DSC06114.JPG DSC_7256