'Solid as a paper Whopper wrapper in the rain': Hackers reported 'catastrophic' cybersecurity flaws at Burger King before the fast food giant nuked their criticism off the 'net via DMCA
The hackers' blog post on the incident can still be accessed via the Wayback Machine.
Keep up to date with the most important stories and the best deals, as picked by the PC Gamer team.
You are now subscribed
Your newsletter sign-up was successful
Want to add more newsletters?
Every Friday
GamesRadar+
Your weekly update on everything you could ever want to know about the games you already love, games we know you're going to love in the near future, and tales from the communities that surround them.
Every Thursday
GTA 6 O'clock
Our special GTA 6 newsletter, with breaking news, insider info, and rumor analysis from the award-winning GTA 6 O'clock experts.
Every Friday
Knowledge
From the creators of Edge: A weekly videogame industry newsletter with analysis from expert writers, guidance from professionals, and insight into what's on the horizon.
Every Thursday
The Setup
Hardware nerds unite, sign up to our free tech newsletter for a weekly digest of the hottest new tech, the latest gadgets on the test bench, and much more.
Every Wednesday
Switch 2 Spotlight
Sign up to our new Switch 2 newsletter, where we bring you the latest talking points on Nintendo's new console each week, bring you up to date on the news, and recommend what games to play.
Every Saturday
The Watchlist
Subscribe for a weekly digest of the movie and TV news that matters, direct to your inbox. From first-look trailers, interviews, reviews and explainers, we've got you covered.
Once a month
SFX
Get sneak previews, exclusive competitions and details of special events each month!
As reported by Tom's Hardware, a pair of hackers successfully compromised the cybersecurity of Restaurant Brands International (RBI), which owns Burger King, Popeyes, and Tim Hortons. They uncovered "catastrophic" vulnerabilities so bad it led the hackers to comment, "We're not even mad, just impressed by the commitment to terrible security practices."
Those "terrible security practices" were alarmingly extensive. The hackers were able to:
- Easily access RBI's Amazon Web Services (AWS) systems.
- Create new user accounts.
- Promote themselves to admin status.
- Access employees' personal information.
- Order store equipment.
- Add and manage stores.
- Access store tablet interfaces.
- Access voice recordings of customers ordering at the drive-thru—which the pair allege are being used to train an AI model.
The pair of hackers explained their project and findings in a blog post that went live on September 6, only to be taken down within 24 hours and replaced with a notice that they received a DMCA complaint from RBI.
Luckily, the original blog post is still visible on the Wayback Machine, where it states: "We stumbled upon vulnerabilities so catastrophic that we could access every single store in their global empire.
"From a Burger King in Times Square to that lonely Tim Hortons where Bugs Bunny shoulda taken a left turn at Albuquerque. Oh, and did we mention we could listen to your actual drive-thru conversations? Yeah, that happened too."
The hackers, "BobDaHacker" and "BobTheShoplifter," have a stated mission of cracking systems to uncover security vulnerabilities and reporting them in an effort to improve security, rather than using this access for their own enrichment.
In terms of fixing the security loopholes the hackers found, the original blog post detailing the RBI hack states that, "RBI's response time was impressive." So, it sounds like at least some of the issues BobDaHacker and BobDaShoplifter found have been resolved, although they also said RBI didn't directly respond to them or comment on the vulnerabilities the hackers reported.
Keep up to date with the most important stories and the best deals, as picked by the PC Gamer team.
It seems the Bobs accomplished what they set out to do, which was uncover and report major security flaws, though RBI thanked them with a DMCA complaint. While it's concerning that RBI apparently had security this weak, it's a good thing the Bobs discovered it before someone else could.
They even closed out their blog post by claiming that they didn't store any data from their project: "No customer data was retained during this research. No drive-thru orders were harmed in the making of this blog post. Responsible disclosure protocols were followed throughout. We still think the Whopper is pretty good, but Wendy's is better. So Long, and Thanks for All the Fish."
2025 games: This year's upcoming releases
Best PC games: Our all-time favorites
Free PC games: Freebie fest
Best FPS games: Finest gunplay
Best RPGs: Grand adventures
Best co-op games: Better together
Stevie Bonifield is a freelance tech journalist specializing in mobile tech, gaming gear, and accessories. Outside of writing, Stevie loves indie games, TTRPGs, and building way too many custom keyboards.
You must confirm your public display name before commenting
Please logout and then login again, you will then be prompted to enter your display name.


