Yet Another Security Breach (YASB) - Marriott Data Breach Affecting 500 million Guests!
Hello Steemians! Security breaches are happening so often these days that I think I will be starting a new tag called "YASB" (Yet another security breach) to track all these posts that I will be posting 😂. Today's victim is Marriott International with 500 million guests affected. Now, let's dive deeper to understand what happened...
Marriott International Data Breach
How many customers were affected?
- Up to approximately 500 million guests who made a reservation at a Starwood property
What information were breached?
- Personal information such as names, mailing addresses, phone numbers, email addresses, passport numbers, Starwood Preferred Guest (“SPG”) account information, dates of birth, gender, arrival and departure information, reservation dates, and communication preferences.
- For some individuals, encrypted payment card numbers and payment card expiration dates. Payment card numbers were encrypted using Advanced Encryption Standard encryption (AES-128).
How did the hack happen?
- There is no official statements on how did the breach happen. Investigations are still going on.
- However, there had been unauthorized access to the Starwood network since 2014 and this was only discovered and stopped on September 10, 2018.
What are the impacts on the company?
- Share price tanked following the hack. Source
- Reputational impact
- Will possibly be fined by regulators and government
- Lawsuits are being filled. Source
How do I know if I am affected? And what should I do if I am?
- If you made a reservation on or before September 10, 2018 at a Starwood property, information you provided may have been involved.
- Starwood brands include: W Hotels, St. Regis, Sheraton Hotels & Resorts, Westin Hotels & Resorts, Element Hotels, Aloft Hotels, The Luxury Collection, Tribute Portfolio, Le Méridien Hotels & Resorts, Four Points by Sheraton and Design Hotels that participate in the Starwood Preferred Guest (SPG) program. Starwood branded timeshare properties are also included.
- Marriott International published this site as a one-stop informational site on this incident.
My Thoughts
The hospitality and tourism industry is being targeted once more by hackers after the 2 recent airlines breaches. The industry is not regulated, hence they usually have a weaker cybersecurity program as compared to the financial sectors. However, the information stored (e.g. personal information and payment cards information) are highly lucrative for hackers. This make the hospitality and tourism industry a popular target.
What bothers me was how long they took to detect the breach which started in 2014. It took the company 4 years to detect that there were unauthorized activities on their database, which is much worse than the average "dwell time" of 191 days.
Dwell time is the duration a threat actor has undetected access in a network until it's completely removed.
Source
I am fortunately not involved in this data breach as the Starwood brands of hotels are too expensive for me. Haha.. But if you are one of those affected, please consider look out of unusual activities on your Starwood membership and credit cards. Thanks for reading and let me know your thoughts on this incident as well!
Projects/Services I am working on:
You can find me in these communities:

What’s worrying is these are the reported (detected) cases. What about the those that goes undetected still
Posted using Partiko iOS
That's so true. Cybersecurity breach is really a question of "not if but when". I agree that there are many organizations that might have been breached but not detected yet
Posted using Partiko Android
Wow.. That's quite a serious breach - 500 million users affected. I guess they were too complacent. To only detect if after 4 years of breach. I can't imagine the aftermath of this breach. I guess some heads will roll and there will be a new IT department. :-)
Yup, 4 years is a long time for a breach to be detected. Whoever in charge of their IT security (if they have any) will certainly have to take full responsibility
Posted using Partiko Android
Thank you so much for participating the Partiko Delegation Plan Round 1! We really appreciate your support! As part of the delegation benefits, we just gave you a 3.00% upvote! Together, let’s change the world!
Hi @culgin!
Your post was upvoted by @steem-ua, new Steem dApp, using UserAuthority for algorithmic post curation!
Your UA account score is currently 3.386 which ranks you at #7116 across all Steem accounts.
Your rank has not changed in the last three days.
In our last Algorithmic Curation Round, consisting of 201 contributions, your post is ranked at #16.
Evaluation of your UA score:
Feel free to join our @steem-ua Discord server