ZeroHour
CyberScooppublished ()ingested @jeffstone500

Marriott says 25 million passport numbers, some unencrypted, involved in massive breach

criticalData breach exploited in the wildimportance 60
Tagsbreach
Full article686 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The breach is the one of the largest ever reported and is under investigation by at least five U.S. states as well as European regulators.

Marriott breach
The front of the Marriott Hotel in Philadelphia. Marriott has revised the amount of people impacted by their data breach. (Getty)

Marriott International said Friday that 383 million customer records were stolen in a data breach last month, down from the hotel chain’s original estimate of 500 million.

Roughly 25.5 million passport numbers also were compromised in the data breach affecting Starwood Hotels reservation system, the company said in a statement. Hackers spent roughly four years inside Starwood’s networks, the company announced Nov. 30.

The breach is the one of the largest ever reported and is under investigation by at least five U.S. states as well as European regulators.

Some 5.25 million of the 25.5 million passports numbers were stored in plain text, Marriott said Friday, providing hackers with a valuable means of stealing individuals’ identities. The hotel chain previously said it would compensate customers for passport replacements if they can prove they had been victims of fraud.

The company also said it believes that approximately 8.6 million encrypted payment cards were involved in the attack.

The roughly 383 million customer files is the “upper limit” of the total number of records involved in the breach, Marriott said. The company “has concluded with a fair degree of certainty that information for far fewer than 383 million” people was involved, adding there are multiple records for the same guests in that database.

“As we near the end of the cyber forensics and data analytics work, we will continue to work hard to address our customers’ concerns and meet the standard of excellence our customers deserve and expect from Marriott,” Arne Sorenson, Marriott’s president and chief executive, said in the statement.

This data breach began in 2014, roughly one year before Marriott International offered to purchase the Starwood hotel chain. Starwood properties include Westin, Sheraton, St. Regis, Aloft and other brands located worldwide.

More Scoops

visitor walks past US multinational telecommunications AT&T logo during the Mobile World Congress (MWC), the telecom industry’s biggest annual gathering, in Barcelona on February 26, 2024. (Photo by PAU BARRENA/AFP via Getty Images)

AT&T agrees to $13 million fine for third-party cloud breach

The breach resulted in the theft of information related to more than 8.9 million AT&T Mobility customers.

A Marriott Hotels sign November 30, 2018, in Chicago, Illinois. (Photo by Scott Olson/Getty Images)

Marriott confirms latest data breach, possibly exposing information on hotel guests, employees

An aerial view from a drone shows the parking lot is nearly empty outside of a Neiman Marcus store that has been shuttered by the COVID-19 pandemic at Oak Brook Center shopping mall on May 07, 2020 in Oak Brook, Illinois. (Photo by Scott Olson/Getty Images)

Neiman Marcus alerts 4.6 million customers about May 2020 data breach

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/marriott-breach-passport-numbers-revision/