marriott sign

Marriott Discloses Second Security Breach, Affecting Millions, In Two Years

The hack took place through Marriott Bonvoy, the company's loyalty app, and affected up to 5.2 million guests.

Disclosing its second major security breach in the past two years, the international hotel chain Marriott announced on Tuesday that a hacker had accessed data affecting up to 5.2 million guests who used Marriott Bonvoy, the company’s loyalty app.

Marriott said the hack first began in mid-February but company officials did not become aware until the end of February. A breach notification published on Marriott’s website details how a hacker used login credentials of two employees at a Marriott property to access customer information from the Bonvoy database.

“Upon discovery, we confirmed that the login credentials were disabled, immediately began an investigation, implemented heightened monitoring, and arranged resources to inform and assist guests,” the breach notification reads.

While the company investigation remains ongoing, Marriott has not found evidence that the hacker accessed account passwords, payment card information, passport information, national ID numbers or driver’s license numbers. The exposed information did include the following:

  • Contact details (e.g., name, mailing address, email address, and phone number)
  • Loyalty account information (e.g., account number and points balance, but not passwords)
  • Additional personal details (e.g., company, gender, and birthday day and month)
  • Partnerships and affiliations (e.g., linked airline loyalty programs and numbers)
  • Preferences (e.g., stay/room preferences and language preference)

Not all of this information was entered for each guest, the company said. Guests involved in the breach were notified by Marriott on Tuesday, and the chain has also set up a self-service online portal for guests to identify if their information was involved in the breach. Affected individuals can also see what categories of information were part of the breach.

Paul Bischoff, a privacy advocate with the tech research and consumer website Comparitech, said that the biggest threat facing Marriott customers in the recent breach is “targeted phishing.”

“Guests should be on the lookout for targeted messages from scammers posing as Marriott or a related company,” Bischoff said. “Don't click on links or attachments in unsolicited emails. Check email addresses and don't just trust display names. If you're uncertain as to whether a message is legitimate or not, ask Marriott using contact information found through Google.”

Back in November 2018, Marriott also disclosed that hackers had accessed personal details of an estimated 500 million guests worldwide through the Starwood Hotels reservation system it had acquired. While the company has since lowered the total to 383 million, Marriott has faced penalties in the U.K. for lax cybersecurity practices. Chinese hackers are suspected in that case.

Andrew Hollister, the director of LogRhythm Labs, noted that there are some positives to draw from Marriott’s disclosure on Tuesday, particularly in the company’s response time to the breach.

“In the previous incident in 2018, Marriott detected signs of unauthorized activity going back four years,” Hollister said. “In this new case, the activity appears to have begun in January 2020 and been detected during the course of February 2020. This is a significant improvement in time to detect and respond to a data breach.”

He added: “This latest data breach just goes to show that continuing vigilance is required to keep reducing the time to detect and respond to threats, and that real reductions in impact can be made with focus on this issue which affects every company on the globe which holds personal information.”

About the Author

Haley Samsel is an Associate Content Editor for the Infrastructure Solutions Group at 1105 Media.

Featured

  • Maximizing Your Security Budget This Year

    7 Ways You Can Secure a High-Traffic Commercial Security Gate  

    Your commercial security gate is one of your most powerful tools to keep thieves off your property. Without a security gate, your commercial perimeter security plan is all for nothing. Read Now

  • Making Safety and Security Intrinsic to School Design

    Public anxieties about school safety are escalating across the country. According to a 2023 Gallup report, 44% of parents fear for their child’s physical safety at school, a 10 percentage-point increase since 2019. Unfortunately, these fears are likely to increase if the incidence of school tragedies continues to mount. As a result, school leaders are now charged with two non-negotiable responsibilities. The first, as always, is to ensure kids have what they need to learn, grow, and thrive. Sadly, their second responsibility is to keep the children in their care safe from threats and physical danger. Read Now

  • The Power of a Layered Approach to Safety

    In a perfect world, every school would have an unlimited budget to help secure their schools. In reality, schools must prioritize what budget they have while navigating the complexities surrounding school security and lockdown. Read Now

  • How a Security System Can Enhance Arena Safety and the Fan Experience

    Ensuring guests have both a memorable experience and a safe one is no small feat for your physical security team. Stadiums, ballparks, arenas, and other large event venues are increasingly leveraging new technologies to transform the fan experience and maintain a high level of security. The goal is to preserve the integrity and excitement of the event while enhancing security and remaining “behind the scenes.” Read Now

Featured Cybersecurity

Webinars

New Products

  • HD2055 Modular Barricade

    Delta Scientific’s electric HD2055 modular shallow foundation barricade is tested to ASTM M50/P1 with negative penetration from the vehicle upon impact. With a shallow foundation of only 24 inches, the HD2055 can be installed without worrying about buried power lines and other below grade obstructions. The modular make-up of the barrier also allows you to cover wider roadways by adding additional modules to the system. The HD2055 boasts an Emergency Fast Operation of 1.5 seconds giving the guard ample time to deploy under a high threat situation. 3

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure. 3

  • FEP GameChanger

    FEP GameChanger

    Paige Datacom Solutions Introduces Important and Innovative Cabling Products GameChanger Cable, a proven and patented solution that significantly exceeds the reach of traditional category cable will now have a FEP/FEP construction. 3