Marriott has admitted that it falsely claimed to have used encryption during a 2018 data breach when it had been using a hashing mechanism called secure hash algorithm 1 (SHA-1). The revelation came during a court case, and Marriott has been ordered to correct the information on its website. Using SHA-1 instead of encryption raises questions about the company’s initial belief and the oversight of forensic investigations. The admission could have serious implications for Marriott, including potential legal consequences and impacts on stock prices.
UnitedHealth’s congressional testimony reveals significant security failures, including paying a $22 million ransom to attackers who breached its systems. The breach occurred due to compromised credentials and the lack of multi-factor authentication on a Change Healthcare Citrix portal. It exposed a large amount of personally identifiable information and personal health information. The impact on data security and the potential for follow-on attacks remain unclear. According to CEO Andrew Witty, approximately a third of US citizens may have been affected by a recent hack. The company is still investigating the breach to determine the exact number of people impacted. It is expected to take several months before victims can be notified.
It is always the lying. Marriott lied to cover up a mistake. That makes everything worse every time.
It’s also often basic stuff: two-factor authentication, encryption, and being ready not to pay a ransom. Many cybersecurity discussions offer tools-based, complex solutions.
And wonder why I keep focusing on passkeys – while not a silver bullet, it sure would go a long way.

