Marriott data breach exposes personal data of 5.2 million guests

The hotel chain has notified guests of a second massive data breach within 18 months

Marriott hotel sign

Marriott has informed 5.2 million guests that their personal details were inappropriately accessed in a possible data breach.

Related Resource

How enterprises are embracing cyber security challenges

Enterprises across Europe, the Middle East and Africa are undergoing a significant transformation

Download now

Contacts details, loyalty account information, company, gender, birthday, partnerships and affiliations and room preferences were among guests’ details accessed between mid-January and February 2020. 

Marriott said this unexpected amount of information was accessed using the login credential of two employees with an application built to provide guest services.

When the firm learned of this activity, the login credentials were disabled, and the company began an investigation, before raising the level of monitoring and arranging resources to inform and assist guests.

“Although our investigation is ongoing, we currently have no reason to believe that the information involved included Marriott Bonvoy account passwords or PINs, payment card information, passport information, national IDs, or driver’s license numbers,” Marriott said.

“If you are uncertain whether your information was involved in the incident, we have set up a self-service online portal for guests to be able to determine whether their information was involved and, if so, what categories of information were involved.”

This is the second major data breach involving the hotel chain after the company was fined £99 million for an incident involving 339 million guests

Marriott revealed in November 2018 that an unknown third-party had gained access to its Starwood guest reservation system by exploiting an unpatched vulnerability from 2014.

Although the number of guests affected by this second data breach represents a fraction of those hit by the 2018 breach, the fact that Marriott is admitting to the second breach in a short space of time should come as a concern.

It’s unclear where the users affected were based, and whether any UK-based guests were affected by the breach. Should UK citizens have been affected, it’s likely the Information Commissioner's Office (ICO) will take a tough stance on the hotel chain, having already issued one massive notice to fine under GDPR rules only last year.

Marriott has said it’s providing guests involved with information about steps they can take, including enrolling into an online information monitoring service provided by IdentityWorks. The firm has also set up a dedicated website and call centre.

Featured Resources

Unlocking collaboration: Making software work better together

How to improve collaboration and agility with the right tech

Download now

Four steps to field service excellence

How to thrive in the experience economy

Download now

Six things a developer should know about Postgres

Why enterprises are choosing PostgreSQL

Download now

The path to CX excellence for B2B services

The four stages to thrive in the experience economy

Download now

Recommended

1Password targets enterprise customers with Secrets Automation
IT infrastructure

1Password targets enterprise customers with Secrets Automation

14 Apr 2021
The definitive guide to IT security
Whitepaper

The definitive guide to IT security

9 Apr 2021
Ubiquiti insider says the company downplayed the severity of a major breach
data breaches

Ubiquiti insider says the company downplayed the severity of a major breach

31 Mar 2021
Forex broker FBS leaves millions of customer records exposed
data breaches

Forex broker FBS leaves millions of customer records exposed

25 Mar 2021

Most Popular

Microsoft is submerging servers in boiling liquid to prevent Teams outages
data centres

Microsoft is submerging servers in boiling liquid to prevent Teams outages

7 Apr 2021
How to find RAM speed, size and type
Laptops

How to find RAM speed, size and type

8 Apr 2021
Xiaomi Redmi Note 10 Pro review: Champagne tastes on a lemonade budget
Mobile Phones

Xiaomi Redmi Note 10 Pro review: Champagne tastes on a lemonade budget

13 Apr 2021