Menu
Browse

McDonald's Canada

Aliases: 2 aliases
Primary URL Location Industry
www[.]mcdonalds[.]ca
Country Canada
Hospitality & Leisure Icon
Hospitality & Leisure
Profile

McDonald's Canada operates as the Canadian subsidiary of the global McDonald's Corporation, providing fast-food restaurant services across the country. Its offerings include burgers, fries, breakfast items, and beverages through physical locations and digital platforms. A key digital service is the MyMcD's mobile application, which enables customers to place orders, accumulate rewards, and manage payments. The app's integration with payment systems positioned it as a convenience tool for frequent patrons seeking streamlined transactions.

In January 2019, McDonald's Canada faced a significant cybersecurity incident involving compromised user accounts on the MyMcD's app. Attackers executed unauthorized food purchases through small, repeated transactions that cumulatively ranged from $50 to over $2,000 per victim. Fraudulent charges often originated from distant geographic locations unrelated to the account holders' actual whereabouts. Some affected customers discovered the activity weeks after it began, as purchase notifications were automatically filtered into email spam folders. One documented case involved 100 unauthorized meal purchases charged to a single account.

McDonald's Canada publicly characterized the incidents as isolated while asserting confidence in the app's security infrastructure. The company declined refunds to multiple victims, redirecting them to seek reimbursement through their financial institutions instead of assuming liability for the breach. This response generated public criticism from customers who emphasized the company's responsibility for securing its application. The breach highlighted vulnerabilities in the app's authentication mechanisms and transaction monitoring, though no technical details about the compromise were disclosed. Customer complaints centered on both the financial impact and McDonald's Canada's refusal to acknowledge systemic flaws in its digital platform.

Incidents
Linked incidents available to members
1 incident