Go Back  FlyerTalk Forums > Miles&Points > Hotels and Places to Stay > Marriott | Marriott Bonvoy
Reload this Page >

Starwood/Marriott Data Breach 500 Million Guests affected, Marriott fined £18.4m

Community
Wiki Posts
Search
Old Nov 30, 2018, 5:05 am
FlyerTalk Forums Expert How-Tos and Guides
Last edit by: MasterGeek
From Starwood Lurker team :
Please visit  info.starwoodhotels.com  for more information about this incident, available resources and steps you can take.

Marriott has announced a massive breach of data belonging to 500 million guests who stayed at hotel brands including W, Sheraton, and Westin.
Marriott announced on Friday that it had "taken measures to investigate and address a data security incident" that stemmed from its Starwood guest authorization database.
The company said it believes that around 500 million people's information was accessed, including an unspecified number who had their credit card details taken. It affects customers who made bookings on or before September 10, 2018.

http://uk.businessinsider.com/marriott-data-breach-500-million-guests-affected-2018-11?r=US&IR=T
https://www.prnewswire.com/news-releases/marriott-announces-starwood-guest-reservation-database-security-incident-300758155.html

You can enroll in the "identity" monitoring service provided by Marriott due to this breach here, it cannot be called "credit monitoring" because it doesn't provide access to viewing credit bureau report data (as held by Equifax, TransUnion, Experian) nor notifications when credit report data changes :
https://answers.kroll.com/us/index.html
Print Wikipost

Starwood/Marriott Data Breach 500 Million Guests affected, Marriott fined £18.4m

Thread Tools
 
Search this Thread
 
Old Dec 3, 2018, 12:42 pm
  #316  
Suspended
 
Join Date: Jul 2001
Location: Watchlisted by the prejudiced, en route to purgatory
Programs: Just Say No to Fleecing and Blacklisting
Posts: 102,095
Originally Posted by CJKatl
That is what the manager indicated in the email. I had made the reservation because they were leaving in a couple weeks and she had not made the reservations, so I was getting nervous. We had been on the phone for hours with various travel providers and she hung up before we finished this last reservation. The manager volunteered to give them lounge access which was much appreciated. I am sorry to see that hotel leave Marriott.

Ironically we got off the phone an hour or so ago making her travel arrangements for Christmas because she was dragging her feet on those.
There is no legal requirement under Czech law for a booked/contracted hotel guest to show up with a passport that matches the passport number submitted at time of booking (or at any time prior to check-in) in order to avail to staying at a Czech hotel under a confirmed hotel booking.
GUWonder is offline  
Old Dec 3, 2018, 12:47 pm
  #317  
 
Join Date: Nov 2017
Posts: 3,359
Originally Posted by GUWonder


There is no legal requirement under Czech law for a booked/contracted hotel guest to show up with a passport that matches the passport number submitted at time of booking (or at any time prior to check-in) in order to avail to staying at a Czech hotel under a confirmed hotel booking.
Agreed on that part. At every hotel I've stayed at in the world (i.e. UK, Germany, Switzerland, USA, New Zealand, Hong Kong, etc.), I was never asked to provide passport data during booking. However, sometimes they did require scanning my passport during check-in. I would expect that collecting such information at time of booking might run into regional privacy legislations such as the German Data Privacy Regulation (GDPR).

Safe Travels,

James
FlyerTalker70 is offline  
Old Dec 3, 2018, 1:07 pm
  #318  
 
Join Date: Feb 2017
Programs: DL DM, UA Gold, Alaska MVP, Bonvoy (lol) Ambassador
Posts: 2,994
Originally Posted by j2simpso
Agreed on that part. At every hotel I've stayed at in the world (i.e. UK, Germany, Switzerland, USA, New Zealand, Hong Kong, etc.), I was never asked to provide passport data during booking. However, sometimes they did require scanning my passport during check-in. I would expect that collecting such information at time of booking might run into regional privacy legislations such as the German Data Privacy Regulation (GDPR).

Safe Travels,

James
While I know that there's a joke in there about Germany running the EU block, the G in GDPR stands for "General" and not "Germany"...
GUWonder likes this.
ethernal is offline  
Old Dec 3, 2018, 1:34 pm
  #319  
Suspended
 
Join Date: Jul 2001
Location: Watchlisted by the prejudiced, en route to purgatory
Programs: Just Say No to Fleecing and Blacklisting
Posts: 102,095
So Marriott hasn’t come clean before?

https://www.forbes.com/sites/thomasb...-breaches/amp/
GUWonder is offline  
Old Dec 3, 2018, 4:19 pm
  #320  
Suspended
 
Join Date: Oct 2009
Location: Kan@da
Programs: Anything with sweet spots
Posts: 1,790
Originally Posted by Starwood Lurker IV
We understand your concern. We began sending emails on Nov 30, 2018 to affected guests. Due to the volume, you may not receive yours immediately. You don’t have to wait for the email if you believe you may be affected. Please visit info.starwoodhotels.com for official information and some steps you can take in response.
Which phone number or email address should I use to contact Marriott to claim compensation? Is Marriott going to take responsibility for their carelessness in handling our personal information and issue a proper and material apology ? A Category 8 7-night certificate would be appropriate.

Last edited by MasterGeek; Dec 3, 2018 at 4:46 pm
MasterGeek is offline  
Old Dec 3, 2018, 4:25 pm
  #321  
FlyerTalk Evangelist
 
Join Date: Jun 2006
Location: IAD/DCA
Posts: 31,797
Originally Posted by GUWonder
I 000000000 in whenever asked for a passport number unless it’s for a flight check-in or an attempt to seek government service. Never had it give me a problem at hotel check-in.
thanks!

500m vs 21m SPG members, although includes post marriott
maybe mostly corporate which dont allow ? and via OTAs ?

wonder how many SPG didnt stay and only used CC for air
or got status via amex plat/cent etc but didnt use at all
my last stay was a long time ago (dont travel much)

500m is clearly a lot of emails

Last edited by Kagehitokiri; Dec 5, 2018 at 12:38 pm
Kagehitokiri is offline  
Old Dec 3, 2018, 7:03 pm
  #322  
 
Join Date: Nov 2015
Location: BNE
Programs: NZ*G, QF Bronze, VA Red
Posts: 563
Originally Posted by Starwood Lurker IV
We understand your concern. We began sending emails on Nov 30, 2018 to affected guests. Due to the volume, you may not receive yours immediately. You don’t have to wait for the email if you believe you may be affected. Please visit info.starwoodhotels.com for official information and some steps you can take in response.
Thanks for that. I am pleased to see that you are notifying people, even if I am a bit dubious that Marriott really can't deliver emails practically instantly - many people have noted that they are still receiving marketing blasts so there's really little excuse there.

I did have a read of your website. Basically it offers some limited guidance and even more limited compensation for people in North America and Europe, but as a resident of Australia all it basically says is "we're really sorry, have some platitudes". No compensation. No practical guidance. Nothing.

It's actually kind of insulting. And I'm more than happy for you to feed back to corporate that insulting customers is a pretty bad way to generate goodwill.
remymartin likes this.
kyanar is offline  
Old Dec 3, 2018, 8:28 pm
  #323  
 
Join Date: Nov 2007
Location: Colorado
Programs: UA Gold (.85 MM), HH Diamond, SPG Platinum (LT Gold), Hertz PC, National EE
Posts: 5,648
My email arrived at 4:46 pm MST today, 12/3/2018. Nothing to discuss that isn't already known.
COSPILOT is offline  
Old Dec 4, 2018, 5:06 am
  #324  
Suspended
 
Join Date: Jul 2001
Location: Watchlisted by the prejudiced, en route to purgatory
Programs: Just Say No to Fleecing and Blacklisting
Posts: 102,095
Originally Posted by COSPILOT
My email arrived at 4:46 pm MST today, 12/3/2018. Nothing to discuss that isn't already known.
It seems to me that so far most people still haven’t gotten any Marriott email about this matter. Many of the people who are covered by GDPR also seem to not have gotten any such email from Marriott. And I’m having the spam folders checked.
GUWonder is offline  
Old Dec 4, 2018, 7:43 am
  #325  
 
Join Date: Apr 2003
Location: SLC/HEL/Anywhere with a Beach
Programs: Marriott Ambassador; AA EXP 3MM; AS MVP, Hilton Gold, CH-47/UH-60/C-23/C-130 VET
Posts: 5,234
Originally Posted by GUWonder


It seems to me that so far most people still haven’t gotten any Marriott email about this matter. Many of the people who are covered by GDPR also seem to not have gotten any such email from Marriott. And I’m having the spam folders checked.
I certainly understand the legal issues regarding notification.

that being said, what information are you expecting to receive in the email that you don't have now?
C17PSGR is offline  
Old Dec 4, 2018, 7:55 am
  #326  
 
Join Date: Mar 2010
Posts: 1,324
Originally Posted by C17PSGR
I certainly understand the legal issues regarding notification.

that being said, what information are you expecting to receive in the email that you don't have now?
I am expecting confirmation that the new Program name "Bonvoy" was created by the hackers and is NOT the actual new name.
HHonors OUTSIDER is offline  
Old Dec 4, 2018, 8:02 am
  #327  
 
Join Date: Feb 2018
Programs: Bonvoy :Ambassador , ALL :Diamond, Skywards :Silver, Krisflyer :Silver
Posts: 2,803
Originally Posted by GUWonder


It seems to me that so far most people still haven’t gotten any Marriott email about this matter. Many of the people who are covered by GDPR also seem to not have gotten any such email from Marriott. And I’m having the spam folders checked.
have you check your fax machine?
KRSW likes this.
kaizen7 is offline  
Old Dec 4, 2018, 8:51 am
  #328  
 
Join Date: May 2004
Location: LAX
Posts: 1,849
2 days later and the world moved on. Like nothing ever happened
dascc likes this.
Big_Foot is offline  
Old Dec 4, 2018, 9:47 am
  #329  
 
Join Date: Apr 2003
Location: SLC/HEL/Anywhere with a Beach
Programs: Marriott Ambassador; AA EXP 3MM; AS MVP, Hilton Gold, CH-47/UH-60/C-23/C-130 VET
Posts: 5,234
Originally Posted by Big_Foot
2 days later and the world moved on. Like nothing ever happened
And like the past four years, there seems to be no evidence of (a) credit card fraud against AMEX or Chase which would be much more easily detected as a pattern than in breaches involving Target/Home Depot, (b) no one with dark web monitoring reporting that their information is up for sale, and (c) no reports of points being stolen. Not sure I've seen anyone pop up and say they've been actually been impacted sometime over the past four years.
kennycrudup and Twickenham like this.
C17PSGR is offline  
Old Dec 4, 2018, 10:21 am
  #330  
 
Join Date: Nov 2017
Posts: 3,359
Originally Posted by GUWonder


It seems to me that so far most people still haven’t gotten any Marriott email about this matter. Many of the people who are covered by GDPR also seem to not have gotten any such email from Marriott. And I’m having the spam folders checked.
It would appear that Marriott is following the BA model of security breach disclosure (i.e. don't disclose at all via email and when disclosed on website it's a small banner buried on the site).

-James
FlyerTalker70 is offline  


Contact Us - Manage Preferences - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.