Massive Security Flaw Exposes Burger King, Popeyes, and Tim Hortons' Global Systems

2025-09-06
Massive Security Flaw Exposes Burger King, Popeyes, and Tim Hortons' Global Systems

Security researchers discovered critical vulnerabilities in the global ordering systems of Restaurant Brands International (RBI), impacting Burger King, Popeyes, and Tim Hortons. Attackers could access data from every store without authentication, including employee information, internal IDs, configuration details, and thousands, possibly hundreds of thousands, of customer voice recordings containing personally identifiable information (PII). The vulnerabilities stemmed from easily exploitable APIs allowing unauthorized user registration and admin access. RBI responded swiftly to patch the vulnerabilities after the report.

Tech