Marriott Starwood hacked

Personal information of over 500 million guests exposed.

Update: 2018-11-30 21:13 GMT
Since May, the world has been rocked by two major international cyber-attacks - the ransomware WannaCry and a likely state-sponsored attack called NotPetya that spread out of Ukraine. (Representational image)

Bethesda(US): The information of as many as 500 million guests at Starwood hotels has been compromised and Marriott said that it’s discovered that unauthorised access within its Starwood network has been taking place since 2014.

The company said on Friday that credit card numbers and expiration dates of some guests may have been taken. For as many as two-thirds of those affected data expo-sed could include mailing address, phone number, email address, passport number, Starwood Preferred Guest account information, date of birth, gender, arrival and departure information, reservation date and communication preferences. For some guests, the information was limited to name and sometimes other data such as mailing address, email address or other information. 

“We fell short of what our guests deserve and what we expect of ourselves,” CE0 Arne Sorenson said in a prepared statement. “We are doing everything we can to support our guests, and using lessons learned to be better moving forward.” 

Email notifications to those who may have been affected will begin rolling out Friday. While the breach affected “approximately 500 million guests” who made a reservation at a Starwood hotel, some of those records could belong to people who had multiple stays. 

When the two companies announced their merger in November 2015, Marriott had 54 million members of its loyalty programme and Starwood had 21 million. Many travelers were members in both programmes. 

Asked for more details on the 500 million number, Marriott spokesman Jeff Flaherty on Friday morning said the company has not finished identifying duplicate information in the database. 

Marriott said that there was a breach of its database in September, which had guest information related to reservations at Starwood properties on or before September 10. An internal security tool signalled a potential breach on September 8, but the company was unable to decrypt the information that would define what data had potentially been exposed.  

Similar News