Go Back  FlyerTalk Forums > Miles&Points > Hotels and Places to Stay > Marriott | Marriott Bonvoy
Reload this Page >

Marriott confirms yet another data breach

Community
Wiki Posts
Search

Marriott confirms yet another data breach

Thread Tools
 
Search this Thread
 
Old Jul 6, 2022, 4:15 pm
  #1  
FlyerTalk Evangelist
Original Poster
 
Join Date: Mar 2014
Location: 4éme
Posts: 12,038
Marriott confirms yet another data breach

Hotel group Marriott International has confirmed another data breach, with hackers claiming to have stolen 20 gigabytes of sensitive data, including guests’ credit card information.

The incident, first reported by Databreaches.net, is said to have happened in June when an unnamed hacking group claimed they used social engineering to trick an employee at a Marriott hotel in Maryland into giving them access to their computer.

“Marriott International is aware of a threat actor who used social engineering to trick one associate at a single Marriott hotel into providing access to the associate’s computer,” Marriott spokesperson Melissa Froehlich Flood told TechCrunch in a statement. “The threat actor did not gain access to Marriott’s core network.”

Marriott said the hotel chain identified, and was investigating, the incident before the threat actor contacted the company in an extortion attempt, which Marriott said it did not pay.

The group claiming responsibility for the attack say the stolen data includes guests’ credit card information and confidential information about both guests and employees. Samples of the data provided to Databreaches.net purport to show reservation logs for airline crew members from January 2022 and names and other details of guests, as well as credit card information used to make bookings.
https://techcrunch.com/2022/07/06/ma...-breach-again/
TomMM is offline  
Old Jul 6, 2022, 4:45 pm
  #2  
 
Join Date: May 2002
Programs: WN F9 HA UA AA IHG HH MR
Posts: 3,305
Another bonvOY enhancement. Lock down your credit bureau inquiries.
njxbean and boss315 like this.
Tanic is offline  
Old Jul 6, 2022, 4:56 pm
  #3  
 
Join Date: Feb 2020
Location: USA
Programs: MB Ambassador, WOH Globalist, HH Diamond (Aspire), AA Gold, UA (*G) Gold
Posts: 5,152
One property and 300-400 people will be notified. Paste the whole article if you want to show the whole story without being alarmist.
ElevatorEnthusiast is offline  
Old Jul 6, 2022, 6:30 pm
  #4  
 
Join Date: Aug 2007
Programs: DL DM
Posts: 1,079
Originally Posted by ElevatorEnthusiast
One property and 300-400 people will be notified. Paste the whole article if you want to show the whole story without being alarmist.
I guess the first breach involving 340 million accounts doesn’t count. Same for the follow-on breach involving 5.2 million guests. I guess Marriott gets a pass on both of these.

You would think they would have learned by now on how to keep data safe
Tanic likes this.
cre95 is offline  
Old Jul 6, 2022, 7:59 pm
  #5  
 
Join Date: Feb 2020
Location: USA
Programs: MB Ambassador, WOH Globalist, HH Diamond (Aspire), AA Gold, UA (*G) Gold
Posts: 5,152
Originally Posted by cre95
I guess the first breach involving 340 million accounts doesn’t count. Same for the follow-on breach involving 5.2 million guests. I guess Marriott gets a pass on both of these.

You would think they would have learned by now on how to keep data safe
I never said anything about those other breaches - my point is that a social engineering attack at a single property is vastly different than those breaches. The OP failed to mention the scope. Assuming that each Marriott property will prevent every breach seems overly harsh, especially when social engineering is involved.
ElevatorEnthusiast is offline  
Old Jul 7, 2022, 7:31 am
  #6  
 
Join Date: Feb 2019
Posts: 3,097
yeah this seems overblown, characterizing this as "another marriott data breach" is sensationalism and extremely misleading
ElevatorEnthusiast likes this.
WillBarrett_68 is offline  
Old Jul 7, 2022, 8:16 am
  #7  
 
Join Date: May 2002
Programs: AAdvantage Platinum, United Silver, Marriott Titanium Elite
Posts: 2,276
Originally Posted by WillBarrett_68
yeah this seems overblown, characterizing this as "another marriott data breach" is sensationalism and extremely misleading
In case anyone wants an overview of how the three known Marriott data breaches compare, here are three links.

The Starwood Hotels reservation system was breached beginning in 2014. This was not discovered until after Marriott acquired Starwood:

Marriott Announces Starwood Guest Reservation Database Security Incident, November 30, 2018 (Marriott News Center)

Then, in 2020, a breach involving stolen employee log-ins affected 5.2 million guests:

Marriott International Notifies Guests of Property System Incident, March 31, 2020 (Marriott News Center)

In the newest (2022) breach, someone obtained access to a computer account at the BWI Airport Marriott, providing visibility to what one hotel associate would be able to access:

Marriott Plays Down 20GB Data Breach, July 7 2022 (Info Security Magazine)
Horace is offline  
Old Jul 7, 2022, 8:32 am
  #8  
 
Join Date: May 2010
Posts: 3,461
If you think ANYONE is safe from this then you are in fantasyland. Your data is not safe at Marriott, Hilton, Hyatt etc.... it's not "if" it's "when"

Truthfully a company hasn't notified you it's probably because they just haven't discovered it yet
Orange County Commuter is offline  
Old Jul 7, 2022, 10:09 am
  #9  
A FlyerTalk Posting Legend
 
Join Date: Apr 2004
Location: GVA (Greater Vancouver Area)
Programs: DREAD Gold; UA 1.035MM; Bonvoy Au-197; PCC Elite+; CCC Elite+; MSC C-12; CWC Au-197; WoH Dis
Posts: 52,139
Originally Posted by Orange County Commuter
If you think ANYONE is safe from this then you are in fantasyland.
One day, a hotel will open up with the claim "We don't use computers, so your data can't be stolen!"
mahasamatman is offline  
Old Jul 7, 2022, 11:09 am
  #10  
 
Join Date: Aug 2008
Location: Somewhere in Florida
Posts: 2,620
Originally Posted by mahasamatman
One day, a hotel will open up with the claim "We don't use computers, so your data can't be stolen!"
My doctor's office still uses paper records and has no plans to "go digital" any time soon.
KRSW is online now  


Contact Us - Manage Preferences - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.