Cyberattack News

Marriott Hacked – Hackers Accessed 5.2 Million Guests Personal Data

Recently, the Hotel chain Marriott revealed a security breach that influenced more than 5.2 million hotel guests who utilized the company’s loyalty app. As per the data breach notification published on its website, the hotel chain determined the security breach at the end of February.

However, later it found that a hacker had applied the login credentials of two employees from one of its franchise resources to get access to the customer data from the app’s backend systems.

Well, Marriott stated in a notice that the hotel chain emphasized the investigation is continuing. So, it had no intention to believe account passwords for Marriott’s Bonvoy rewards plans or financial data such as credit card numbers, passport data, or driver’s licenses were accessed.

Whereas, Tyler Carbone, the chief strategy officer at digital risk protection provider Terbium Labs, stated that the breach could be uncertain for consumers. “From what we know of the data disclosed, this is the kind of data that gives the proper raw material for cybercrime.”

However, Marriott conveyed an email on Tuesday to the affected customers from marriott@email-marriott.com and fastened up a dedicated website where customers can present a demand to check to see if their information was affected in the data breach or not.

What Happened?

Well, the Hotels operated and franchised below Marriott’s brands utilize an application to help implement services to guests at hotels. But, at the end of February 2020, we recognized that a surprising amount of guest data might have been obtained utilizing the login credentials of two employees at a franchise business, as we told earlier.

Hence, they consider that this activity commenced in mid-January 2020. As a result, they reinforced that the login credentials were useless, immediately started an investigation, performed heightened monitoring, and established resources to inform and help guests.

What information was accessed?

Through their investigation is continuing, recently, they have no reason to accept that the information associated included Marriott Bonvoy account passwords or PINs, payment card data, passport data, national IDs, or driver’s license numbers.

At this circumstance, they believe that the following data may have been included, but not all of this information was being included for every guest:-

  • Contact details like email, mailing address, name, and phone number.
  • Additional personal details like birth date, gender, and company.
  • Loyalty Account Information like points balance and account number but not passwords.
  • Partnerships and Affiliations like linked airline loyalty programs and numbers.
  • Preferences like language preference and stay/room preferences.

Well, if you are unsure whether your information was affected in the conflict, they have set up a self-service online portal for customers to be prepared to conclude whether their data was involved and, if so, what sections of information were affected.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

16 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

16 hours ago