Breach Notification , Incident & Breach Response , Security

New Post Public Reply Private Reply Replies (4) Message Board
CyberC
492
Breach Notification , Incident & Breach Response , Security Operations

Marriott Suffers Another Massive Data Breach

Employees' Credentials Used to Steal 5.2 Million Customers' Personal Details


By: Scott Ferguson (@Ferguson_Writes) • March 31, 2020

another-marriott-breach-affects-millions-showcase_image-8-a-14036.jpg

Hotel giant Marriott in 2018 disclosed that it had suffered one of the worst data breaches in history. On Tuesday, Marriott warned that it has suffered a second big data breach, this time exposing information on 5.2 million customers.

See Also: Live Webinar | More Data, More Problems: Applying the Right Automation to Propel Security Operations

This most recent data breach began around mid-January and continued until the end of February, and apparently did not expose payment card information, Marriott says in its data breach notification. But the breach did expose email addresses, mailing addresses, Bonvoy - aka loyalty - rewards numbers and other personally identifiable information.

"Although Marriott's investigation is ongoing, the company currently has no reason to believe that the information involved included Marriott Bonvoy account passwords or PINs, payment card information, passport information, national IDs or driver's license numbers," Marriott says.


Alan Woodward

@ProfWoodward
Today’s data breach is brought to you by Marriott (again) https://mysupport.marriott.com/




Incident Notification
mysupport.marriott.com
3
7:29 AM - Mar 31, 2020
Twitter Ads info and privacy
See Alan Woodward's other Tweets
Marriott says it carries cyber insurance.

Mega-Breach, Take Two
The new breach alert follows Marriott in November 2018 announcing that its Starwood guest reservation database had been hacked, exposing approximately 339 million customer records. Exposed data included names, mailing addresses, phone numbers, email addresses, passport numbers and, in some cases, encrypted payment card information.

That breach eventually led Britain's Information Commissioner's Office, the country's privacy watchdog, to propose that Marriott be fined approximately $125 million under the EU's General Data Protection Regulation (see: Marriott Faces $125 Million GDPR Fine Over Mega-Breach). Marriott is appealing the fine, and experts say the legal uncertainty caused by Britain having now formally exited the EU may require the EU to launch a new investigation.

Marriott has over 7,300 hotel and guest properties in 134 countries and territories around the world. In addition to the Marriott name, its 30 brands include W Hotels, St. Regis, Sheraton Hotels & Resorts, Westin Hotels & Resorts, Element Hotels, Aloft Hotels, The Luxury Collection, Tribute Portfolio, Le Méridien Hotels & Resorts, Four Points by Sheraton and Design Hotels. In 2019, the company had $20.9 billion in revenue.

Potentially Stolen: Employee Credentials
In the most recent data breach, Marriott is investigating whether the login credentials assigned to two employees who worked at one of the company's properties were used to access an application that helps provide services to customers, the company says in its notification.

It's not clear whether the two workers are under investigation for accessing the system or had their passwords and usernames stolen or phished.

A spokesman for Marriott could not be immediately reached for comment.

"The company believes that this activity started in mid-January 2020," Marriott says in its breach notification. "Upon discovery, the company confirmed that the login credentials were disabled, immediately began an investigation, implemented heightened monitoring and arranged resources to inform and assist guests. Marriott also notified relevant authorities and is supporting their investigations."

While details about this latest breach are currently scarce, there are two obvious ways that this security incident could have occurred, says Chris Pierson, CEO of cybersecurity firm BlackCloak.

"The first is that a legacy system is being accessed online without dual-factor authentication and without a proper gateway," Pierson tells Information Security Media Group. "The second is that this was a credential compromise as a result of an infected system, phishing or credential stuffing attack. The key here is to have log-in anomaly detection, dual-factor authentication on all system as well as data exfiltration analytics."

One cause for concern is that Marriott said attackers had potentially compromised stored passwords, which could imply the company was storing these passwords in plaintext, which would make them easier to steal or abuse, says Jake Williams, a former hacker with the National Security Agency's Tailored Access Operations unit and founder of Rendition Infosec.

"The fact that there's no clarification about the passwords and PINs being hashed would suggest that they were not," Williams tells ISMG. "I would normally wait for clarification on this from an organization, but given that they've already been through this recently, I would expect they reviewed this [breach notification] for technical accuracy before publication."

Extensive Personal Data Exposed
Customer personally identifiable information that appears to have been exposed over a two-month period includes:

Contact details, including name, mailing address, email address and phone number;
Loyalty account information, including account numbers and points balances but not passwords;
Personal details, including companies customers worked for, gender and birth day and month;
Partnerships and affiliations, including airline loyalty programs and numbers linked with Marriott accounts;
Hotel preferences, including room and language preferences.
Marriott says not all of these records were exposed for every customer affected by the breach. The company has created a dedicated website and call center for customers that may have been affected.

In the company's earlier breach incident, Marriott said attackers accessed the customer reservation network for its Starwood properties starting in 2014, but the breach was not detected and disclosed until late in 2018. The breach notably persisted past September 2016, which is when Marriott International completed its acquisition of Starwood Hotels & Resorts Worldwide for $13 billion (see: Banks: Starwood Breach Not Isolated).

Latest Breach Detected Relatively Quickly
The biggest difference between the two breaches is that Marriott appears to have detected the latest intrusion much more quickly, Pierson says. "The landscape of a distributed company with franchises is difficult to manage. This is why cybersecurity needs to be deployed at every endpoint and entryway," he says.

Brian Honan, president of Dublin-based cybersecurity consultancy BH Consulting, says that it appears that Marriott over the last two years has improved its security monitoring capabilities. That's the likely reason why it discovered the January intrusion relatively quickly - by the end of February - thus preventing even more customer records from potentially being exposed.

"It is unclear whether the staff accounts used to compromise the data were somehow hijacked and used by malicious third parties, or if the accounts used were the result of an insider," Honan tells ISMG. "Regular monitoring for suspicious activity and restricting access to data are key controls to prevent such a breach from happening, and again it is good to see Marriott taking steps to enhance those controls."

Different Regulatory Landscape
Another notable difference between 2018, when the earlier Marriott breach was disclosed, and the new breach, is that the company may face additional legal scrutiny, beyond even GDPR in Europe. For example, if any of the breached records involves California residents, this breach might prove to be a test case for the California Consumer Privacy Act, says Richard Santalesa, a technology and data privacy attorney at SmartEdgeLaw Group, a boutique law firm with offices in New York and Connecticut.

"Despite the ongoing pandemic and California Attorney General's Office regulations still not being finalized, the AG's office has said that enforcement will not be delayed and will start July 1, 2020, and look retroactively back to Jan. 1, 2020, when CCPA kicked off," Santalesa says. "So, the Marriott breach could be a CCPA enforcement matter - potentially."

Executive Editor Mathew Schwartz contributed to this report.

Zerify Inc (ZRFY) Stock Research Links

ZRFY Board Company Profile Buy Rating Time & Sales News Filings Financials
Scroll down for more posts ▼

Top 10 Most Recent News Articles

Deadline Looms for EquipmentShare Investors' Legal Action

Updated Category News Views 4

Pressure Builds for EquipmentShare Investors If you've thrown some cash into EquipmentShare.com Inc. (NASDAQ: EQPT), it's time to sit up and pay attention. There's smoke on the horizon, and Faruqi & Faruqi, LLP is waving the flag. They've got a securities class action spinning fast, and if you've suffered any losses, September 21, 2026, is a date you don't want to forget....

Continue Reading
XKL Delivers MediaLight for High-Speed Optical Transport

Updated Category News Views 2

Unpacking the MediaLight Launch Kicking off September, XKL is tossing its hat in the ring with the MediaLight Xponder and Muxponder systems. These aren't just any run-of-the-mill gizmos—nope, they're touted as top-of-the-line optical transport solutions. The talk of the town is their ability to dish out high-density 100G and 400G transport, and for geeks in the trade,...

Continue Reading
Rare Collectibles Highlight Morphy's Auction on Oct 4

Updated Category News Views 2

Anticipation Builds for Morphy's Auction Event Morphy's upcoming event on October 4th is all about tapping into the era of revved engines, gleaming gasoline signs, and some history that could put Hollywood tales to shame. The auction isn't just a stroll down memory lane; it features over 650 lots, each a time capsule of America's automotive past. From Al Capone's ritzy...

Continue Reading
Veteran Marketer Joins The Wisory's Advisory Board

Updated Category News Views 3

Tyrrell Schmidt Joins The Wisory's Board Out of the blue, The Wisory has snatched Tyrrell Schmidt right off the retirement bench. This doesn't seem like just another board seating; it smells like a calculated power play. Schmidt, fresh from her heavyweight stint as Global CMO at TD Bank, adds a spicy dose of marketing prowess to The Wisory's already loaded Advisory Board....

Continue Reading
K-9 Hero Act Aims to Ease Costs for Retired Dogs' Care

Updated Category News Views 7

Let's Talk About the Loyalty that Dogs Deserve Who would've thought we'd be chatting about our four-legged heroes in a federal setting? But here we are, giving well-deserved attention to those furry federal agents. They're the ones who sniff out bombs and tackle crooks, and they're not asking for a retirement plan with a yacht – just some vet care! What the K-9 Hero Act...

Continue Reading
GBI Bio's New CEO Jesse McCool to Propel Growth

Updated Category News Views 4

Jesse McCool stepping into GBI's CEO shoes is the kind of move that makes you sit up straight and take notice. Let me tell you, the biomanufacturing scene is buzzing with this appointment, and McCool's got his work cut out for him in leading GBI Biomanufacturing's shift towards commercial-scale operations while expanding their early-stage biotech portfolio. A Veteran in...

Continue Reading
OneAscent Welcomes Monica Stoudemire as New CCO

Updated Category News Views 3

New Leadership in Compliance Diving straight into the tumultuous sea of securities compliance, OneAscent's got a fresh captain at the helm. Monica Stoudemire's stepped into the Chief Compliance Officer's shoes with a track record that'd make any investor breathe a sigh of relief. After all, blending two decades of on-the-ground experience with regulatory acumen ain't...

Continue Reading
Albertsons Welcomes Once Upon a Coconut Nationwide

Updated Category News Views 4

Coconut Water Takes Over Grocery Aisles You know, for all the cautious optimism I wield, this here is a move that shows real muscle in the world of coconut water—I mean, slamming into Albertsons' grocery empire is no small potatoes! Once Upon a Coconut has landed its premium hydration cans across all the banners under this giant retailer. From that good ol' familiar...

Continue Reading
Mobile Iron IV Expansions: Targeting Texas Health Needs

Updated Category News Views 14

Out in Texas, folks facing iron deficiency have a new game-changer coming their way. Drip Gym, the same outfit making waves out in Queens and Long Island, is taking their mobile iron IV therapy clinic straight to Texan doorsteps. No more trotting off to a clinic for iron infusions with this crew rolling into Houston, Dallas, Austin, and San Antonio. What's the Big Deal?...

Continue Reading
AbbVie's Bold Leap in Menstrual Migraine Treatment

Updated Category News Views 10

AbbVie's Game-Changing Atogepant Study When it comes to pushing boundaries in the pharmaceutical world, there's no sitting on the fence. AbbVie's Phase 3 LUNA study results are painting a bright picture for women who suffer from the relentless grip of menstrual migraines. In a world where not a single treatment option has been approved specifically for this condition,...

Continue Reading

Top 5 Most Recently Viewed Articles

Jacobs Announces Quarterly Dividend with Shareholder Benefits

Updated Category News Views 167

Jacobs Declares Quarterly Cash Dividend The Board of Directors of Jacobs (NYSE:J) has recently announced a quarterly cash dividend aimed at rewarding its shareholders. This dividend reflects the company’s robust financial standing and commitment to delivering value to its investors. Jacobs has set the dividend amount at $0.32 per share of common stock, which exemplifies...

Continue Reading
Arquus Achieves ISO 27001 Certification with MAGNA's Help

Updated Category News Views 113

Arquus Attains ISO 27001 Certification: A Game Changer Arquus, a visionary in defense and vehicle innovation, has reached an incredible milestone by securing the ISO 27001 information security management certification. This significant accomplishment has been made possible through the expert guidance of MAGNA, a recognized leader in cybersecurity services. Commitment to...

Continue Reading
Sewell Automotive Expands with New Land Rover Dealership Acquisition

Updated Category News Views 335

Sewell Automotive's New Venture into Luxury Vehicles Sewell Automotive Companies, a cherished Texas-based dealership group, has recently made headlines by acquiring Land Rover Boerne. This significant move marks Sewell's expansion into the Boerne area and enhances their commitment to providing exceptional service within the luxury vehicle market. About the Acquisition...

Continue Reading
Royal Canadian Mint's Remarkable Achievement in Coin Design

Updated Category News Views 271

Royal Canadian Mint's Recent Coin Awards Triumph The Royal Canadian Mint has recently made headlines by receiving global industry recognition for its remarkable achievements in coin design at the Mint Directors Conference. This esteemed event is celebrated annually, honoring excellence in commemorative and circulating coin production worldwide. Outstanding Double-Sided...

Continue Reading
Groundbreaking Hydrogen Production Pilot with SunHydrogen and UT Austin

Updated Category News Views 253

Exciting Collaboration for Renewable Hydrogen Production SunHydrogen, Inc. (OTCQB: HYSR) has taken a significant leap forward in renewable energy technology by partnering with The University of Texas at Austin. This strategic collaboration aims to set up a pioneering hydrogen production pilot system larger than 30 m², showcasing the innovative potential of...

Continue Reading