The Challenge
McDonald's Indonesia exposed over 40 million records through an unsecured customer data platform. This included 28 million customer records with names, emails, phone numbers, and device IDs, as well as over 71,000 corporate records related to advertising campaigns. Cybernews discovered the open database, highlighting immediate risks for social engineering attacks and loyalty fraud.
Though the database is now secured, the incident underscores a recurring issue: customer engagement platforms often lack adequate access controls, leaving both customer and corporate data vulnerable.
Regulatory and Security Challenges
Modern loyalty and engagement platforms intersect with multiple regulatory frameworks. Consider these factors:
PCI DSS scope questions. If your loyalty platform stores Primary Account Number (PAN) data or interacts with payment authorization, it falls under PCI DSS requirements. Even without direct card processing, shared infrastructure or integrated APIs can bring adjacent systems into scope.
GDPR and regional privacy laws. Customer names, emails, and phone numbers are personal data under the General Data Protection Regulation and similar laws. Device IDs can link to other datasets, expanding breach notification obligations.
Corporate data exposure. The advertising campaign records in this incident highlight a category often overlooked. Marketing data can include customer segmentation, spending patterns, and campaign metrics that competitors or fraudsters could exploit.
The main issue is that these platforms are often deployed by marketing teams who don't see them as security-critical. You might only learn about them during an audit or, worse, after an incident.
Necessary Security Measures
After Cybernews reported the exposure, the database was closed. However, proactive measures could have prevented this:
Network segmentation and access controls. Ensure customer data platforms are behind authentication layers with Role-Based Access Control (RBAC). Public internet access to production databases is a basic security violation. Implement network-level restrictions to limit connections to authorized servers.
Data classification and retention policies. Not all customer interactions need indefinite storage. Define retention windows based on business needs and regulatory requirements, then enforce automated purging. Less data means a smaller blast radius if something goes wrong.
Regular access audits. Platforms often ship with default credentials or permissive access settings. Conduct quarterly audits to verify authentication, check for exposed endpoints, and ensure only authorized personnel can access customer records.
Monitoring for unusual access patterns. Your security information and event management system should flag large data queries. Set thresholds for bulk exports and configure alerts for access from unexpected IP ranges.
Impact and Consequences
The database was secured after external discovery. It's unclear if McDonald's Indonesia faced regulatory penalties or how many customers were notified. However, 28 million customer records are now in unknown hands. Email addresses and phone numbers can fuel phishing and vishing attacks for years. Loyalty fraud becomes easier when attackers correlate customer IDs with transaction histories.
Corporate data exposure poses competitive risks. Campaign performance data reveals which promotions work and how the company structures its marketing.
Steps to Improve Security
Start with discovery. You can't secure platforms you don't know exist. Conduct quarterly scans of your cloud infrastructure and SaaS subscriptions. Marketing teams often deploy platforms without involving IT or security. Implement approval workflows requiring security review before new platforms go live.
Implement defense in depth for systems handling customer data:
Authentication at multiple layers. Require Multi-Factor Authentication (MFA) for administrative access. Use short-expiration API keys for application-to-database connections. Don't rely solely on network obscurity.
Encryption in transit and at rest. Encrypt customer records using industry-standard algorithms. For sensitive fields like loyalty point balances, consider field-level encryption with separate Key Encryption Keys (KEK).
Least Privilege for database access. Service accounts should have only necessary permissions. Separate read-only analytics access from production write access.
Automated security testing. Include customer data platforms in regular vulnerability scans and penetration tests. Treat them with the same rigor as payment processing systems.
Takeaways for Your Team
Map your data platform landscape. Survey departments interacting with customers. Document platforms storing names, emails, phone numbers, transaction histories, or device IDs. Classify them by sensitivity and regulatory scope.
Build security requirements into procurement. Before signing contracts for new platforms, require vendors to complete a security questionnaire. Ask about configurations, access control, encryption options, and incident response history.
Test for public exposure quarterly. Use external scanning tools to check if databases, APIs, or storage buckets are accessible without authentication. Verify configurations.
Prepare your breach response plan for loyalty fraud. Expand breach playbooks to cover loyalty point theft, account takeovers, and social engineering using transaction histories. Define notification thresholds and assign communication responsibilities.
Integrate loyalty platforms into your threat model. Treat these systems as in-scope for security reviews. Include them in your asset inventory and monitor their access logs diligently.
The McDonald's Indonesia incident wasn't sophisticated. It was a database left open. This pattern should concern you most: not advanced threats, but the platforms deployed without your team's knowledge.





