{"id":32481,"date":"2025-07-18T13:41:32","date_gmt":"2025-07-18T17:41:32","guid":{"rendered":"https:\/\/www.oxebridge.com\/emma\/?p=32481"},"modified":"2025-07-18T13:41:32","modified_gmt":"2025-07-18T17:41:32","slug":"paradox-ai-responsible-for-123456-password-breach-holds-iso-27001-and-soc2-certifications","status":"publish","type":"post","link":"https:\/\/www.oxebridge.com\/emma\/paradox-ai-responsible-for-123456-password-breach-holds-iso-27001-and-soc2-certifications\/","title":{"rendered":"Paradox AI, Responsible for &#8220;123456&#8221; Password Breach, Holds ISO 27001 and SOC2 Certifications"},"content":{"rendered":"<p>Paradox, a Scottsdale-based company that sells AI assistant tools for large enterprises, is reported to have used a known poor password, enabling data from clients such as McDonald&#8217;s and Lockheed Martin to be compromised. Originally reported in <a href=\"https:\/\/www.wired.com\/story\/mcdonalds-ai-hiring-chat-bot-paradoxai\/\">WIRED<\/a>, McDonald&#8217;s revealed that its Paradox-powered AI chatbot &#8220;<em>Olivia<\/em>&#8221; had been breached due to &#8220;<em>absurdly basic<\/em>&#8221; security flaws:<\/p>\n<blockquote><p>&#8230; the Olivia chatbot, built by artificial intelligence software firm Paradox.ai, also suffered from absurdly basic security flaws. As a result, virtually any hacker could have accessed the records of every chat Olivia had ever had with McDonald&#8217;s applicants\u2014including all the personal information they shared in those conversations\u2014with tricks as straightforward as guessing that an administrator account&#8217;s username and password was \u201c123456.&#8221;<\/p><\/blockquote>\n<p>In response, Paradox issued a <a href=\"https:\/\/www.paradox.ai\/blog\/responsible-security-update#toc--what-did-not-happen\">public blog post<\/a> that insisted &#8220;<em>we want to emphasize that this incident impacted one Paradox client instance<\/em>.&#8221; Brian Krebs, the security researcher and writer for Krebs on Security, has challenged that assertion, however, <a href=\"https:\/\/krebsonsecurity.com\/2025\/07\/poor-passwords-tattle-on-ai-hiring-bot-maker-paradox-ai\/\">revealing<\/a> other troubling problems with Paradox&#8217;s lax security:<\/p>\n<blockquote><p>However, a review of stolen password data gathered by multiple breach-tracking services shows that at the end of June 2025, a Paradox.ai administrator in Vietnam suffered a malware compromise on their device that stole usernames and passwords for a variety of internal and third-party online services.<\/p>\n<p>[The] purloined credentials show the developer in question at one point used the same seven-digit password to log in to Paradox.ai accounts for a number of\u00a0Fortune 500 firms listed as customers on the company\u2019s website, including\u00a0Aramark,\u00a0Lockheed Martin,\u00a0Lowes, and\u00a0Pepsi.<\/p><\/blockquote>\n<p><span style=\"font-size: 18pt;\"><strong>ISO 27001 &#8220;Assurances&#8221;<\/strong><\/span><\/p>\n<p>Meanwhile, Paradox has held both ISO 27001 and SOC 2 security certifications since 2019, according to the company&#8217;s <a href=\"https:\/\/www.paradox.ai\/news\/paradox-receives-iso-27001-and-soc-2-type-ii-security-certifications\">press releases<\/a>.\u00a0<span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">These certifications were issued by A-LIGN, which is then accredited by ANAB in the United States.\u00a0<\/span><\/p>\n<p>ISO 27001 requires the implementation of security controls, which are then defined in greater detail in the supporting standard, ISO 27002. The controls for passwords, as defined in ISO 27002, attempt to prevent the exact problem shown by Paradox:<\/p>\n<blockquote><p>When passwords are used as secret authentication information, select quality passwords with sufficient minimum length which are&#8230; not based on anything somebody else could easily guess [and] free of consecutive identical, all-numeric or all-alphabetic characters.<\/p><\/blockquote>\n<p>ISO 27002 also requires that &#8220;<em>encryption keys are long enough to resist brute force attacks.<\/em>&#8221;<\/p>\n<p>Nevertheless, third-party ISO 27001 certification was granted to Paradox and even reissued after the problem was reported. ISO 27001 certification is marketed by both A-LIGN and ANAB as being able to &#8220;<em>assure<\/em>&#8221; the security of data and conformity to the standard, which would include those password requirements.<\/p>\n<p>A-LIGN repeatedly claims it &#8220;<em>tests<\/em>&#8221; the controls defined in ISO 27001, even though typical audits rely primarily on interviews and reviews of pre-existing documentation, rather than actual testing. From the A-LIGN <a href=\"https:\/\/www.a-lign.com\/service\/iso-27001-certification\">page<\/a> on ISO 27001 (emphasis added):<\/p>\n<blockquote><p><span class=\"NormalTextRun SCXW255171273 BCX0\"><span class=\"NormalTextRun BCX0 SCXW171720437\">Is your system conformed to the ISO 27001 standard?\u00a0<\/span><em><strong><span class=\"NormalTextRun BCX0 SCXW171720437\">Let us\u00a0<\/span><span class=\"NormalTextRun BCX0 SCXW171720437\">test and confirm.<\/span><\/strong><\/em><span class=\"NormalTextRun BCX0 SCXW171720437\">This part\u00a0<\/span><span class=\"NormalTextRun BCX0 SCXW171720437\">of the audit\u00a0<\/span><span class=\"NormalTextRun BCX0 SCXW171720437\">includes<\/span><span class=\"NormalTextRun BCX0 SCXW171720437\">\u00a0interviews, inspection of documented evidence, and process observation.<\/span><\/span><\/p>\n<p><span class=\"NormalTextRun SCXW255171273 BCX0\">&#8230; we conduc<\/span><span class=\"NormalTextRun SCXW255171273 BCX0\">t annual surveillance audits to <em><strong>ensure your ongoing conformity<\/strong><\/em> with the ISO 27001 standard\u00a0<\/span><span class=\"NormalTextRun SCXW255171273 BCX0\">and<\/span><span class=\"NormalTextRun SCXW255171273 BCX0\">\u00a0give you the\u00a0<\/span><span class=\"NormalTextRun SCXW255171273 BCX0\">peace of mind<\/span><span class=\"NormalTextRun SCXW255171273 BCX0\">\u00a0that your systems and processes\u00a0<\/span><span class=\"NormalTextRun SCXW255171273 BCX0\">are<\/span><span class=\"NormalTextRun SCXW255171273 BCX0\"> compliant.<\/span><\/p><\/blockquote>\n<p>A-LIGN then says its certification &#8220;<em>builds a culture of information security and diligence<\/em>&#8221; and &#8220;<em>reduces security incidents through implemented controls specific to your unique risks and assets.<\/em>&#8221;<\/p>\n<p>ANAB, meanwhile, has aggressively marketed its accreditation as being able to &#8220;<em>assure<\/em>&#8221; results.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-32483\" style=\"border: 1px solid #000000;\" src=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2025\/07\/ENSURE-03-LinkedIn-07-28-2023.jpg\" alt=\"\" width=\"400\" height=\"403\" \/><\/p>\n<p>ANAB went further and repeatedly marketed its accreditation as a tool companies can use in court to provide <em>&#8220;an added layer of legal defensibility against invalid claims<\/em>.&#8221;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-32482\" style=\"border: 1px solid #000000;\" src=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2025\/07\/ANAB_-22-02-2022b.png\" alt=\"\" width=\"400\" height=\"356\" \/><\/p>\n<p><span style=\"font-size: 18pt;\"><strong>SOC 2 Type II Assurances<\/strong><\/span><\/p>\n<p>In addition, Paradox holds SOC 2 certification. According to <a href=\"https:\/\/secureframe.com\/hub\/soc-2\/what-is-soc-2\">Secureframe<\/a>:<\/p>\n<blockquote><p>SOC 2 is a security framework that specifies how organizations should protect customer data from unauthorized access, security incidents, and other vulnerabilities. The American Institute of Certified Public Accountants (AICPA) developed SOC 2 around five\u00a0Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy.<\/p>\n<p>During a SOC 2 audit, an independent auditor will evaluate a company\u2019s security posture related to one or all of these Trust Services Criteria. Each TSC has specific requirements, and a company puts internal controls in place to meet those requirements.<\/p><\/blockquote>\n<p>Specifically, Paradox holds an SOC 2 &#8220;<em>Type II<\/em>&#8221; certification, which is alleged to be more rigorous than Type I. Type II reports attest to the company&#8217;s information security practices on the basis of how the specific TSC controls perform over a period of time, typically 3-12 months. As a result, SOC 2 Type II is harder to achieve, but is marketed as being more robust.<\/p>\n<p>This level, as opposed to Type I, is marketed as being able to &#8220;<em>assure<\/em>&#8221; the company&#8217;s data is protected. Per the A-LIGN <a href=\"https:\/\/www.a-lign.com\/service\/soc-2\">website<\/a>:<\/p>\n<blockquote><p>Assure your customers and partners you are protecting their information with a SOC 2 assessment report from the top\u00a0SOC 2\u00a0report issuer in the world.<\/p><\/blockquote>\n<p>And:<\/p>\n<blockquote><p>In a SOC 2 audit,\u00a0A-LIGN\u00a0will review your policies, procedures, and systems that protect information across five categories called Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy). As your independent SOC 2 auditor,\u00a0A-LIGN\u00a0evaluates the evidence you supply for the controls in each category, resulting in a SOC 2 report.<\/p>\n<p>The benefits of a SOC 2 report &#8230; provides assurance to your customers and partners that your systems are secure.<\/p><\/blockquote>\n<p><span style=\"font-size: 18pt;\"><strong>Certification Re-Issued After Public Disclosure<\/strong><\/span><\/p>\n<p>It raises serious questions about the veracity of both A-LIGN and ANAB marketing claims if so many audits could have been conducted on Paradox systems without anyone noticing <span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">that Paradox AI passwords had been set to &#8220;<em>123456<\/em>,&#8221; which Paradox admitted was a &#8220;<em>legacy password<\/em>.&#8221; Given that Paradox&#8217;s ISO 27001 certificate was initially issued in 2019, it would mean that Paradox<\/span>\u00a0underwent at least six audits by A-LIGN during that time.<\/p>\n<p><span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">More troubling is the fact that, according to IAF CertSearch, the certificate to Paradox was updated by A-LIGN on July 16, 2025, <em><strong>after<\/strong><\/em><em>\u00a0<\/em>the McDonald&#8217;s passwork scandal was reported in the mainstream press.<\/span><\/p>\n<p><a href=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2025\/07\/paradoxaicert.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-32484\" style=\"border: 1px solid #000000;\" src=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2025\/07\/paradoxaicert.png\" alt=\"\" width=\"500\" height=\"759\" \/><\/a>A-LIGN also <a href=\"https:\/\/www.a-lign.com\/service\/cmmc-certification\">reports<\/a> it is an official C3PAO auditing body for the CMMC program, which also asserts to have the ability to prevent such incidents.<\/p>\n<p><span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">In 2024, A-LIGN\u00a0<a href=\"https:\/\/www.a-lign.com\/resources\/a-lign-achieves-iso-42001-accreditation\" target=\"_blank\" rel=\"noopener\">began issuing ISO 42001 certifications<\/a> for AI management<\/span>\u00a0systems, also under ANAB accreditation, even though the rules for certification bodies under the ISO 42001 scheme are still in draft.<\/p>\n<p><span style=\"font-size: 14pt;\"><strong>History of Scandal<\/strong><\/span><\/p>\n<p>To date, a host of ANAB-accredited ISO 27001 certificates have been issued to companies later found to be in violation of the standard.<\/p>\n<ul>\n<li style=\"--tw-scale-x: 1; --tw-scale-y: 1; --tw-scroll-snap-strictness: proximity; --tw-ring-offset-width: 0px; --tw-ring-offset-color: #fff; --tw-ring-color: #3b82f680; --tw-ring-offset-shadow: 0 0 #0000; --tw-ring-shadow: 0 0 #0000; --tw-shadow: 0 0 #0000; --tw-shadow-colored: 0 0 #0000;\">In 2019, the international security firm Prosegur was <a href=\"https:\/\/www.oxebridge.com\/emma\/prosegur-hacked-worldwide-yet-holds-iso-27001-info-security-certification\/\">hacked, <\/a>while holding ISO 27001 certification by AENOR, accredited by multiple accreditation bodies, including ANAB.<\/li>\n<li style=\"--tw-scale-x: 1; --tw-scale-y: 1; --tw-scroll-snap-strictness: proximity; --tw-ring-offset-width: 0px; --tw-ring-offset-color: #fff; --tw-ring-color: #3b82f680; --tw-ring-offset-shadow: 0 0 #0000; --tw-ring-shadow: 0 0 #0000; --tw-shadow: 0 0 #0000; --tw-shadow-colored: 0 0 #0000;\">In 2021, NASA contractor Digital Management Inc. <a href=\"https:\/\/www.oxebridge.com\/emma\/nasa-contractor-hit-with-ransomware-attack-holds-iso-27001-other-certifications-from-sri\/\">suffered<\/a> a ransomware attack while holding ISO 27001 issued by SRI and accredited by ANAB.<\/li>\n<li style=\"--tw-scale-x: 1; --tw-scale-y: 1; --tw-scroll-snap-strictness: proximity; --tw-ring-offset-width: 0px; --tw-ring-offset-color: #fff; --tw-ring-color: #3b82f680; --tw-ring-offset-shadow: 0 0 #0000; --tw-ring-shadow: 0 0 #0000; --tw-shadow: 0 0 #0000; --tw-shadow-colored: 0 0 #0000;\">In 2023, the company Airtable was <a style=\"--tw-scale-x: 1; --tw-scale-y: 1; --tw-scroll-snap-strictness: proximity; --tw-ring-offset-width: 0px; --tw-ring-offset-color: #fff; --tw-ring-color: #3b82f680; --tw-ring-offset-shadow: 0 0 #0000; --tw-ring-shadow: 0 0 #0000; --tw-shadow: 0 0 #0000; --tw-shadow-colored: 0 0 #0000;\" href=\"https:\/\/www.oxebridge.com\/emma\/iso-27001-certified-company-found-leaking-childrens-data-takes-no-action\/\">reported<\/a>\u00a0to have been leaking children&#8217;s personally identifiable information (PII) while holding ISO 27001 issued by BARR Certifications, also accredited by ANAB.<\/li>\n<li>Okta was <a href=\"https:\/\/www.oxebridge.com\/emma\/okta-breach-occurred-while-company-held-iso-27001-certification-from-schellman\/\">breached<\/a> in 2023, in a hack that affected &#8220;all&#8221; its customers, while holding ISO 27001 issued by Schellman and accredited by ANAB.<\/li>\n<li>In 2024, Fidelity Investments was <a href=\"https:\/\/www.oxebridge.com\/emma\/fidelity-investments-hit-with-data-breach-while-holding-iso-27001-certification\/\">hacked<\/a> while holding ISO 27001 certification issued by NQA and accredited by ANAB.<\/li>\n<\/ul>\n<p>In all cases, the certifications were never withdrawn or suspended. Neither the certification bodies nor ANAB were ever questioned on the scandals.<\/p>\n<p>In 2018, Equifax suffered a highly publicized and <a href=\"https:\/\/www.oxebridge.com\/emma\/equifax-held-iso-27001-certification-at-time-of-massive-system-hack\/\">massive breach<\/a> despite holding ISO 27001 certification by EY CertifyPoint. Investigators later found that Equifax&#8217;s security hardware was decades old, but it had never been discovered by the third-party auditors. That certification was issued by the Dutch accreditation body RvA. The certification was only withdrawn after EY CertifyPoint closed its operations.<\/p>\n<p><span style=\"font-size: 18pt;\"><strong>Pay to Play<\/strong><\/span><\/p>\n<p>At the heart of the problem is the ISO certification scheme&#8217;s built-in conflicts of interest: each party pays the auditing body above them.\u00a0The accreditation bodies, including ANAB, then justify the scheme on a suspect and flawed &#8220;<em>peer review<\/em>&#8221; program to self-attest that they comply with the standard for accreditation bodies, ISO 17011. These reviews are widely reported to be conducted by conflicted, untrained, and unqualified volunteers and result in no actions even when major complaints and criminal allegations are made against the accreditation bodies.<\/p>\n<p>The IAF, which oversees the entire scheme, then goes to\u00a0<span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">extremes to avoid any accountability. Recently, the IAF adopted a &#8220;<em>vexatious complainant policy<\/em>&#8221; that allows its members, including ANAB, to dismiss complaints, including reports of possible<\/span> crimes, without taking action. The VP of ANAB, Lori Gillespie, is co-chair of the IAF, and ANAB has adopted a policy of rejecting complaints wholesale, without regard to the veracity of each complaint.<\/p>\n<p>Nevertheless, governments rely on the scheme primarily due to a lack of transparency regarding the scheme&#8217;s conflicts of interest.<\/p>\n<p>Accredited certification bodies and auditors typically defend the certification scheme by insisting that third-party auditors at bodies like A-LIGN and ANAB are not tasked with identifying specific weaknesses, and that audits only capture a snapshot of the system as it was presented on the day of the audit. This effectively concedes that audits will not result in the promises made by the associated marketing, contradicting their &#8220;<em>assurances<\/em>.&#8221;<\/p>\n<p>Nevertheless, both certification and accreditation bodies refuse to withdraw such certifications even after breaches, violations, and lack of conformity are reported by the mainstream press. As a result, poor-performing companies maintain their certification, allowing them to continue gaining access to Federal contracts.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>","protected":false},"excerpt":{"rendered":"<p>Paradox AI was recertified to ISO 27001 by A-LIGN after the scandal was reported.<\/p>","protected":false},"author":644,"featured_media":32490,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","mc4wp_mailchimp_campaign":[],"footnotes":""},"categories":[3],"tags":[8746,50,7679,938,65,8745,8747],"class_list":["post-32481","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-a-lign","tag-anab","tag-cmmc","tag-cybersecurity","tag-iso-27001","tag-paradox-ai","tag-soc-2","et-has-post-format-content","et_post_format-et-post-format-standard"],"_links":{"self":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts\/32481","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/users\/644"}],"replies":[{"embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/comments?post=32481"}],"version-history":[{"count":5,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts\/32481\/revisions"}],"predecessor-version":[{"id":32491,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts\/32481\/revisions\/32491"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/media\/32490"}],"wp:attachment":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/media?parent=32481"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/categories?post=32481"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/tags?post=32481"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}