
In a significant development surrounding the 2018 data breach, Marriott International confessed in a court hearing on April 10 that it had misrepresented the encryption level used to safeguard sensitive data. Initially asserting Advanced Encryption Standard 128 (AES-128), the hotel chain admitted to employing a less secure method, Secure Hash Algorithm 1 (SHA-1), during the breach period.
During proceedings at the US District Court for the District of Maryland Southern Division, Judge John Preston Bailey instructed Marriott to promptly rectify any misinformation on its website. However, Marriott discreetly updated a webpage from 2019 without issuing a formal announcement.
Questions linger regarding Marriott’s initial claim and third-party firms’ oversight of forensic investigations. Douglas Brush, a specialist in federal court matters, emphasized the potential ramifications, including contractual breaches and stock market implications.
The discrepancy between AES-128 and SHA-1 encryption methods has sparked concern among cybersecurity experts. Fuad Hamidli and Phil Smith highlighted the vulnerability of SHA-1 compared to the robustness of AES-128.
Plaintiffs’ attorneys argued that Marriott’s misidentification hindered fraud detection efforts, as SHA-1 encryption is easily penetrable. They contended that vital information might have been lost due to encryption claims’ false sense of security.
However, Marriott’s legal representative, Lisa Ghannoum, countered these assertions, stating that relevant data is preserved despite the encryption error. Ghannoum emphasized that independent assessments initially corroborated Marriott’s encryption claims.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543