McDonald’s McHire Breach Shows Why APIs Need Non-Human Identity and Strong Auth
A default password and unauthenticated API exposed 64M McDonald’s job applicants. We break down what went wrong—and how Non-Human Identity and workload authentication could’ve prevented it.
Heather Howland
July 11, 2025