IOTW: Marriott International suffers latest in series of data breaches

Hospitality company Marriott International reports data breach result of social engineering hack

Add bookmark
IOTW: Marriott International suffers latest in series of major data breaches

Update: This article has been updated to reflect the scale of the breach, which affected 300-400 individuals

Hotel group Marriott International has reported that it has suffered its third major data breach of the past eight years as hackers gained access to one of its customer databases. 

The latest incident in a string of attacks was reported to have happened in June 2022 when an anonymous hacking group used social engineering in order to gain access to an employee’s computer. 

The unnamed group reportedly told DataBreaches that they were able to exfiltrate 20 GB of data including "some confidential and proprietary information".

Marriott spokesperson Melissa Froehlich Flood said in a statement that the company was "aware of a threat actor who used social engineering to trick one associate at a single Marriott hotel into providing access to the associate’s computer", but that "the threat actor did not gain access to Marriott’s core network". 

Froehlich Flood also stated that the information accessed primarily contained non-sensitive internal business files regarding the operation of the property, and that Marriott identified and was investigating the incident before the threat actor contacted the company in an extortion attempt, which Marriott did not pay.

Following the incident, the company is preparing to notify 300-400 individuals, in addition to notifying law enforcement.

Social engineering is an attack vector where hackers will attempt to gain access to data through psychologically manipulating people into breaking usual security procedures. This then allows the bad actors unauthorized access to confidential or sensitive information. 

The first data breach, which took place in 2014 but was not detected until 2018, allowed hackers access to customer data including but not limited to names, email addresses, passport information, flight information including arrival and departure times, loyalty program numbers and VIP status. 

The hotelier was fined US$15.4m in 2018 for failing to have proper safeguards in place, with an estimated 339 million customers affected by its first data breach. This data breach involved a hacker gaining unauthorized access to a database containing information for over 500 million guests.

The second breach, which affected an estimated 5.2 million people, took place in January 2020.   


More From Incident of the Week

IOTW: Victoria Court recordings exposed in suspected ransomware attack

Unauthorized access disrupted audio visual in-court technology network impacting video recordings, a...

 2024-01-05  by Michael Hill
IOTW: Victoria Court recordings exposed in suspected ransomware attack

IOTW: Xfinity data breach impacts 35 million customers

Exposed data includes usernames, hashed passwords and social security numbers

 2023-12-22  by Michael Hill
IOTW: Xfinity data breach impacts 35 million customers

IOTW: Russia-linked cyber attack targets Ukraine’s biggest phone operator

Powerful attack knocked out internet access and mobile communications, damaging IT infrastructure

 2023-12-15  by Michael Hill
IOTW: Russia-linked cyber attack targets Ukraine’s biggest phone operator

IOTW: HTC confirms cyber attack as BlackCat ransomware gang teases stolen data

BlackCat/ALPHV ransomware group leaked photos of what appears to be stolen passports, contact lists,...

 2023-12-08  by Michael Hill
IOTW: HTC confirms cyber attack as BlackCat ransomware gang teases stolen data

IOTW: Okta data breach affects all customer support users

Hackers stole information on all users of Okta’s customer support system

 2023-12-01  by Michael Hill
IOTW: Okta data breach affects all customer support users

Recommended

info@cshub.com/r/n

We hope you enjoy All Access from CS Hub!!<\/p>\r\n<p>Best Regards,<\/p>\r\n<p><a href=https://www.cshub.com/"https:////www.cshub.com///" target=\"_blank\">CS Hub Team<\/a><\/p>\r\n<p>P.S. Be sure to check out our other upcoming <a href=https://www.cshub.com/"https:////www.cshub.com//events?filter_format=ONLINE\%22 target=\"_blank\">All Access events here<\/a>.<\/p>\r\n<p>--------------------------------<\/p>\r\nConnect with us on Social Media: <a href=https://www.cshub.com/"https:////www.linkedin.com//groups//12067996///" target=\"_blank\">LinkedIn<\/a> | <a href=https://www.cshub.com/"https:////twitter.com//CSHubUSA/" target=\"_blank\">Twitter<\/a><\/p>\r\n<p>--------------------------------<\/p>\r\n<p>FAQS<\/p>\r\n<p><b>Can I invite my colleagues?<\/b><br>Yes of course! Please send them this link so they can register for free! [WebUrl]<\/p>\r\n\r\n<p><b>How do I access the sessions?<\/b><br>\r\nAll Access is run on Zoom Events. You should receive an email shortly from Zoom Events with your unique All Access link to the event lobby. Please hold on to that email ahead of the event. We\u2019ll also send you a reminder 24 hours before we go live!<\/p>\r\n\r\n<p><b>Will the agenda be updated?<\/b><br>\r\nYes, the agenda will be continuously updated on the website with the latest sessions & speakers. As we get closer to the event, also look out for our weekly updates which will also include the latest updates information and link to access the event.<\/p>\r\n<p><b>Can I access the sessions On Demand?<\/b><br>\r\nEvery session will be available after the event via the event lobby. We\u2019ll also send you a reminder about the On Demand sessions which will be sent to you after the event is over.<\/p>\r\n<p>--------------------------------<\/p>\r\n<p>RELATED RESOURCES TO READ BEFORE YOUR EVENT<\/p>\r\n<ul>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//executive-decisions//reports//cs-hub-mid-year-market-report-2022?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CS Hub Mid-Year Market Report 2022<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//ciso-strategies-for-proactive-threat-prevention?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CISO strategies for proactive threat prevention<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//how-to-strengthen-email-security-and-protection-against-advanced-ransomware-attacks?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">How to strengthen email security and protection against advanced ransomware attacks<\/a><\/li>\r\n<\/ul>","event_registration_srs_confirmation_email":null,"assets_from_cdn":true},"bant_disabled":1,"sponsorship_disclaimer":null,"sponsorship_disclaimer_text":null,"sponsorship_disclaimer_checkbox_disabled":0,"ext_treat_id":null,"recording_url":null,"file_attachment":null,"ingo_enabled":null,"ingo_activator_id":null,"ingo_autofiller_id":null,"ingo_amplifier_id":null,"ingo_authorizer_id":null,"restricted_content":0,"featured_events_embedded":[],"featured_content_embedded":[{"id":"5d7fc01ae3899108ea272c29","name":"Behind The Data Breach: Understanding Cloud Security And Misconfigurations","description":"A Look Into Cloud Services And The Shared Responsibility Model","file":null,"url":"\/cloud\/articles\/behind-the-data-breach-understanding-cloud-security-and-misconfigurations"},{"id":"609bd82fd1d92e49596f6604","name":"Data Loss Prevention (DLP) in the Pandemic Era: Trends & Emerging Solutions ","description":null,"file":null,"url":"\/executive-decisions\/articles\/data-loss-prevention-dlp-in-the-pandemic-era-trends-emerging-solutions"},{"id":"606b4cf9d1d92e26fa20f823","name":"Data Privacy 2021: How Data Privacy is Becoming a Strategic Priority","description":"Data privacy is rapidly evolving from a compliance challenge to a strategic objective. Here is what you need to know.","file":null,"url":"\/data\/articles\/data-privacy-2021-how-data-privacy-is-becoming-a-strategic-priority"},{"id":"5d9b8549d1d92e0ea916c6d2","name":"IOTW: Multiple Yahoo data breaches across four years result in a $117.5 million settlement","description":"Phishing And Nation State Attacks Lead To Mega-Breach Of Former Leading Email Provider","file":null,"url":"\/attacks\/articles\/incident-of-the-week-multiple-yahoo-data-breaches-across-4-years-result-in-a-1175-million-settlement"}],"featured_content_portal_embedded":null}" >