A bug in McDonald's Monopoly VIP game in the UK caused login names and passwords for the game's database to be sent to all winners.

See also: Google: Removes popular Android apps that stole Facebook credentials
McDonald's UK launched its popular Monopoly VIP game on August 25, where customers can enter codes found in grocery stores to win prizes. These prizes include £100,000 in cash, a villa in Ibiza or a holiday in the UK, a hot tub and more.
Unfortunately, the game experienced an issue over the weekend after an error caused usernames and passwords to be sent to database servers in redemption emails sent to winners.
An unspecified screenshot of the email sent to the winners shows an exception error, including sensitive information about the web application.
See also: Australian jailed for operating subscription services with stolen credentials
This information included hostnames for Azure SQL databases and the database login names and passwords, as shown in the following repurposed email sent to a VIP Monopoly winner.
The award winner who shared the email said that the production server was disabled by a firewall, but that they could access the staging server using the included credentials.
Since these databases may have contained won prize codes, they could have allowed a dishonest person to download unused codes to claim the prizes.
Luckily for McDonald's, the individual responsibly disclosed the issue to McDonald's. Unfortunately, this wasn't an isolated incident, as other users reported seeing the credentials and went so far as to share their experience in a TikTok video.
See also: Hackers abuse Google Forms / Telegram to collect phished credentials
While the bug clearly stated that both production and staging server credentials were leaked, McDonald's told BleepingComputer that it was only the staging server that was exposed.
Information source: bleepingcomputer.com
