FlyerTalk Forums - View Single Post - Marriott announces new data breach; up to 5.2 million guests affected
Old Mar 31, 2020, 7:59 am
Mr. Vker
Join Date: Feb 2006
Location: Cockeysville, MD
Programs: Marriott Rewards Lifetime Titanium, Amex Plat, Hertz Gold 5*, National Exec, AA Plat
Posts: 9,453
Another Marriott Data Breach??

Didn't see a thread on this. Last night I suddenly had to change my PW and use 2 factor authentication the 3 times I logged in. Got the email below this morning.

​​​​​​Dear Valued Guest, We are writing to let you know that some of your information may have been accessed without authorization. We are sorry that this occurred, and this message explains what happened, how we can assist you, and steps you can take.
What Happened Hotels operated and franchised under Marriott’s brands use an application to help provide services to guests at hotels. At the end of February 2020, we identified that an unexpected amount of guest information may have been accessed using the login credentials of two employees at a franchise property. We believe this activity started in mid-January 2020. Upon discovery, we confirmed that the login credentials were disabled, immediately began an investigation, implemented heightened monitoring, and arranged resources to inform and assist guests. Your information was among the information that appears to have been accessed.
What Information Was Involved Although Marriott's investigation is ongoing, we currently have no reason to believe that the information involved included Marriott Bonvoy account passwords or PINs, payment card information, passport information, national IDs, or driver’s license numbers.

At this point, we believe that the following information may have been involved, although not all of this information was present for every guest involved: ● contact details (e.g., name, mailing address, email address, and phone number) ● loyalty account information (e.g., account number and points balance, but not passwords) ● additional personal details (e.g., company, gender, and birthday day and month) ● partnerships and affiliations (e.g., linked airline loyalty programs and numbers) ● preferences (e.g., stay/room preferences and language preference)
What We Are Doing ● We have set up a dedicated website ( where you can find more information. ● We have also established dedicated call center resources, which can be reached by calling the numbers below. The call center resources will be staffed during ordinary business hours in the United States, 8:00am-8:00pm EDT Monday through Friday. Language support will be provided in English and French, and additional translation services will be available upon request.
Location Number
United States/Canada +1-800-598-9655
Australia 1800280257
France 0805540130
Germany 08006644414
United Kingdom 08003457018
Rest of the World (toll may apply) +1-402-952-5356

● Where available, Marriott is offering guests involved the option to enroll in IdentityWorks, a personal information monitoring service, free of charge for 1 year. This service will be provided by Experian, a global data and information services provider. This is an optional service that allows you to identify information that you would like to have the service monitor; how much information to include in the monitoring is completely up to you. Any information that you provide to Experian will only be used by Experian for the sole purpose of the monitoring service. Due to regulatory and other reasons, IdentityWorks or similar products are not available in all countries/regions. IdentityWorks is currently available in Australia, Brazil, Canada, Germany, Hong Kong, India, Ireland, Italy, Mexico, New Zealand, Poland, Singapore, Spain, the United Kingdom, and the United States. Language support for online enrollment is available in English, French, French Canadian, German, Italian, Portuguese, and Spanish. ○ To use IdentityWorks to start monitoring your personal information please follow the steps below: ◾ Ensure that you enroll by June 30, 2020 (your code will not work after this date.) ◾ Visit the Experian IdentityWorks website to enroll: • US Residents: • Non-US Residents: ◾ Provide your activation code: • US Residents: 2CZM8QXV6 • Non-US Residents: 3F23BXQ3X ● If you are a Marriott Bonvoy member: ○ Even though we currently have no reason to believe that passwords were involved in the incident, we have disabled your existing Marriott Bonvoy password, so when you log in to your Marriott Bonvoy account at, you will be prompted to change your password. ○ You will also be prompted to enable multi-factor authentication to further protect access to your account. ● We have notified relevant authorities and are supporting their investigations.
Additional Steps You Can Take To guard against the information involved being used for phishing or social engineering attempts or attempts to access and use the points in your Marriott Bonvoy account, you can take a number of precautionary steps, in addition to enrolling in IdentityWorks: ● If you have a Marriott Bonvoy account but have not activated your online access to it and set up a password, you should do so now. ● Use good password management practices, including not using easily guessed passwords and not using the same password across multiple accounts. ● Monitor your Marriott Bonvoy account for any activity that you did not initiate and notify us of any suspicious activity. ● You should not provide any information—especially payment card information, other financial account information, online account information, or passwords—to anyone who calls or otherwise contacts you purporting to be from Marriott or a Marriott brand hotel. Marriott will never call or email you to ask you to provide this information by phone or email. ● You should be vigilant against possible “phishing” emails that appear to be (but are not) sent from Marriott email addresses.
Again, we are sorry that this occurred. If you have any further questions, you can contact us by: ● Visiting our dedicated website: ● Calling us at the numbers listed above
Stephanie C. Linnartz
Group President, Consumer Operations, Technology and Emerging Businesses
Mr. Vker is offline