Marriott reveals massive database breach affecting up to 500 million hotel guests

Marriott reveals massive database breach affecting up to 500 million hotel guests

6 years ago
Anonymous $L9wC17otzH

https://www.theverge.com/2018/11/30/18119403/marriott-database-breach-starwood-hotels

Marriott is revealing a massive database breach today, affecting up to 500 million guests of its Starwood hotels the company first acquired in 2016. A security investigation has concluded that there was “unauthorized access” to a database holding hotel guest records. “Marriott learned during the investigation that there had been unauthorized access to the Starwood network since 2014,” says a statement from the company. The breach includes 327 million records of “some combination” of name, mailing address, phone number, email address, passport number, Starwood Preferred Guest (“SPG”) account information, date of birth, gender, arrival and departure information, reservation date, and communication preferences.

Marriott isn’t providing an exact number, but “some” hotel guests will have had their payment card information leaked. Marriott did encrypt this information using Advanced Encryption Standard encryption (AES-128), but the company notes both components needed to decrypt payment card numbers may have been stolen.