Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallA 2026 report says a publicly accessible McDonald’s Indonesia customer-data database contained 28 million customer records, as part of a larger database with more than 40 million records. The report, published by Security Magazine and crediting Cybernews researchers, lists names, email addresses, phone numbers and device IDs among the customer data. It says the database was later closed, but does not establish whether anyone accessed or copied the information before then.
What the report says was exposed
Security Magazine’s account of Cybernews researchers’ findings describes a McDonald’s Indonesia customer data platform whose database held more than 40 million records overall. Of those, 28 million were reported as customer records containing names, email addresses, phone numbers and device IDs. The database reportedly also contained more than 71,000 advertising-campaign records. Security Magazine’s report
Those figures are record counts, not a verified count of distinct people. The reporting does not establish that 28 million individual customers were affected, nor does it say that the records were accessed or downloaded by an unauthorized party. It does not list passwords, payment-card details or government identifiers among the exposed fields.
What is known—and what is not
Known from the report
- The database was publicly accessible and, according to the report, has since been closed.
- The reported customer-record fields included names, email addresses, phone numbers and device IDs.
- The database reportedly included loyalty-point transaction information, prompting researchers to warn of possible loyalty fraud.
Not established by the reporting
- When the database became publicly accessible or how long it remained open.
- Whether unauthorized people viewed or copied records.
- Whether customers were individually notified, or whether fraud or scam attempts have resulted.
- The precise loyalty transaction fields involved or how the database was exposed.
Closure means the database is no longer publicly accessible according to the report; it does not prove that nobody accessed it beforehand. The reviewed report does not provide an incident statement from McDonald’s Indonesia.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
What should customers do?
- Be cautious with unexpected contact. Treat unsolicited emails, texts or calls about McDonald’s, account access or loyalty points carefully. Do not follow an unexpected link or give a password or verification code in response to an unsolicited message.
- Check your loyalty account directly. Open the official McDonald’s app or website yourself and review account and points activity. If something looks unfamiliar, contact McDonald’s using a channel you know is official.
- Change a reused password. If you used the same password for a McDonald’s account and other services, change it and use a unique password. Passwords were not among the fields listed in the report; this is a precaution, not evidence they were exposed.
- Use the local privacy channel for questions or rights requests. Privacy rights depend on the country and applicable law. McDonald’s U.S. privacy statement describes rights such as access, correction and deletion where applicable, but it is not an Indonesia-specific notice or remedy. U.S. readers can consult McDonald’s U.S. privacy statement; readers elsewhere should use their local McDonald’s privacy information and relevant data-protection authority.
Cybernews researchers warned that affected individuals could face increased social-engineering attempts by email or phone and possible loyalty fraud. Those are risks identified by researchers, not confirmation that scam messages or account fraud have occurred.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Do not confuse this with other McDonald’s data reports
The 28 million figure refers to the reported Indonesia customer-platform exposure. Separate coverage published in August 2026 concerned TheHatman’s claim to sell 1.7 million alleged McDonald’s Corporation employee-directory records associated with Azure or Entra. Cybernews reported that the sample link did not work when its researchers checked and that the access method was unclear; TechRadar Pro also covered the claim. Those are allegations about a different set of records, not evidence about the Indonesia customer database. Cybernews’ report and TechRadar Pro’s report
A 2025 Polish regulator finding about employee scheduling information at McDonald’s Polska is another distinct incident; it does not establish facts about the Indonesia exposure. Poland’s UODO statement
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

