Marriott International disclosed that attackers had gained unauthorised access to the Starwood guest reservation database, which it had acquired in 2016. It initially said up to around 500 million guests could be affected. Starwood brands included Sheraton, Westin, and W Hotels.
What happened
- The intrusion dated back to 2014, before Marriott bought Starwood, and was discovered in September 2018.
- Data included names, addresses, phone numbers, email addresses, passport numbers, and, for some guests, encrypted payment card details.
- Marriott later revised the figure to around 383 million guest records.
- The UK ICO fined Marriott £18.4m in 2020, and media reports linked the attack to Chinese state-backed hackers, which China denied.
Why it mattered
It was one of the largest breaches ever disclosed and highlighted the security risks that companies inherit through mergers and acquisitions. Marriott later said more than five million unencrypted passport numbers were involved.
Lessons for organisations
Carry out cyber security due diligence before acquisitions, integrate or replace acquired systems quickly, and minimise retention of sensitive data such as passport numbers. Detection tools should also be reviewed so that long-running intrusions are found sooner.
Source: CNN
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.