09/04/2025
This security breach recently suffered by McDonald's should serve as a reminder to adhere to established cybersecurity practices. McDonald's invested millions to develop their "McHire" application processing system, yet they set the table for the compromise of 64 million records by failing to utilize the most basic password protections. According to Ryan Galluzo, who leads NIST’s Digital Identity Program, “The worst password I can think of is ‘password’ or ‘12345.’” McDonald's used "123456." NIST guidance recommends a password of at least 15 characters. At 100 billion guesses per second, it would take a computer more than five hundred years to guess all the possible combinations of 15 lowercase letters. In addition to complex passwords, ensure to employ multifactor authentication wherever possible!
McDonald’s AI-powered hiring system exposed millions of applicants’ personal data due to basic security flaws, raising urgent questions about trust and AI automation.