Marriott suffers a massive breach of its guest records. Here’s how to protect yourself

Marriott gives update on its hack, says millions of passport numbers were stolen

The data of as many as 383 million travelers could have been compromised in a breach of Marriott’s Starwood Preferred Guest (SPG) database. After originally sharing information about the breach in November, the company released updated information on January 4, with fewer guests affected but some unencrypted passport numbers involved the breach. Marriott says an internal security tool recently alerted the company to the breach, but an investigation showed the unauthorized access began in 2014. The breach only includes the Starwood Preferred Guest loyalty program — guests who booked at a Marriott-owned property from another booking platform were not affected.

Marriott originally estimated that as many as 500 million guests may have had data compromised by the breach, though the company hasn’t yet completed the investigation. That number is now lower, with the company estimating as many as 383 million affected. For some guests, Marriott says payment card numbers and expiration dates were compromised. That payment data was encrypted, Marriott says, but the investigation hasn’t yet determined if the components needed to decrypt the data were also compromised.

Now, Marriott also says that around 5.25 million unencrypted passport numbers were also stolen, along with more than 20 million encrypted numbers. The company also says that payment information was only compromised for a small percentage of those affected by the breach  — around 8.5 encrypted numbers were affected, but a majority of those cards have already expired.

The company shared in November that around 327 million guests had non-payment-related data compromised, which can include their name, mailing address, phone number, email address, passport number, SPG account data, birth date, and gender, along with details like arrivals and departures, reservation dates, and communication preferences. Other guests had more limited data compromised, such as name, email, and mailing address, the company says.

“We deeply regret this incident happened,” Arne Sorenson, Marriott’s president and chief executive officer, said in a press release. “We fell short of what our guests deserve and what we expect of ourselves. We are doing everything we can to support our guests, and using lessons learned to be better moving forward.”

The breach affected accounts using the SPG platform between 2014 and September 10, 2018. Marriott says affected guests were notified by email, and the call center can help guests determine if their passport numbers were part of the breach. The company is also offering a dedicated website and call center for affected users, as well as a free year of WebWatcher. The breach was also reported to law enforcement agencies.

“Today, Marriott is reaffirming our commitment to our guests around the world,” Sorenson said. “ We are working hard to ensure our guests have answers to questions about their personal information, with a dedicated website and call center. We will also continue to support the efforts of law enforcement and to work with leading security experts to improve. Finally, we are devoting the resources necessary to phase out Starwood systems and accelerate the ongoing security enhancements to our network.”

The SPG breech joins other recent data hacks inside the travel industry, including those affecting Orbitz, British Airways, and Cathay Pacific.

What can you do to protect yourself?

This incident is particularly severe because it includes the possible loss of payment card numbers, expiration dates, and other payment data. This data was encrypted, but that doesn’t mean it’s safe. Even the loss of address and phone number information is significant since it can be used to help criminals defraud victims.

Vivek Lakshman, vice president of Innovation at biometric security company ThumbSignIn, sees a reason for concern. “This is huge in its depth of knowledge about the customer and the reach of millions of customers,” he said. “If the information reaches the dark web, as it happens with other breaches, it can get to other hackers and can have a cascading impact on consumer accounts.”

If you’ve stayed at Marriott lately, or are otherwise worried that your data was compromised, you can protect yourself by using the usual methods. According to Lakshman, that includes changing your passwords, enabling two-factor authentication, and signing up for the Webwatcher service that Marriott has offered. You can take an even more extreme, and effective, step by freezing your credit. This will prevent criminals from using the compromised information to open new lines of credit in your name.

What will the consequences be for Marriott? That’s hard to say. Lakshman told Digital Trends that “apart from massive loss of customer trust, there are likely government fines for Marriott.” Yet he seemed skeptical that these fines will be substantial, adding that “[…] with the rate of breaches happening, even this will pass and be forgotten from consumer memory in a few years.”

Updated January 4, 2019: Added updated data from Marriott. 

Smart Home

After camera hacks, Nest locks customers out until they change their password

Nest is locking people out of their accounts if it believes there may have been a breach. Users will have to set up a new, secure password before they are able to regain access to their account.
Business

Marriott asking guests for data to see if they were victims of the Starwood hack

Marriott has created an online form to help you find out if your data was stolen in the massive Starwood hack that came to light toward the end of 2018. But take note, it requires you to submit a bunch of personal details.
Mobile

Happy Valentine’s Day! Coffee Meets Bagel dating app data may have been breached

Are you planning on using Coffee Meets Bagel to find love on Valentine's Day? If you've been using the app for a while, you'll probably want to change your password -- the company said a data breach may have taken place before May 2018.
Computing

500px reveals almost 15 million users are caught up in security breach

Almost 15 million members of portfolio website 500px have been caught up in a security breach. The hack occurred in 2018 but was only discovered last week. Users are being told to change their 500px password as soon as possible.
Mobile

Allstate’s SquareTrade buys phone repair service iCracked

Allstate may be looking to diversify its service a little. The company announced that SquareTrade, a company Allstate owns, is buying iCracked, a popular phone repair service that currently operates in more than 60 cities.
Mobile

T-Mobile says Sprint merger will boost 5G speeds by up to 6 times

2019 will be a huge year for T-Mobile. Not only is a merger with Sprint likely, but T-Mobile is also in the midst of building out its next-generation mobile service. Here's everything you need to know about the T-Mobile 5G rollout.
Mobile

Verizon wants you to lobby the government for 5G deployment

Verizon is in the midst of a massive 5G rollout. In addition to fixed 5G service, it will also begin deploying mobile 5G in the coming months. Here's everything you need to know about Verizon's 5G network and when it will be in your town.
Mobile

Sprint’s 5G rollout: Everything you need to know about it

Sprint is building its next-gen 5G network in preparation for a 2019 rollout, but it's taking a decidedly different approach than some of its competitors, including Verizon and AT&T. Here's everything you need to know.
Mobile

Smartwatch sales soared in 2018, with Apple leading the charge

The NPD Group, a market research organization, has reported smartwatch sales soared in 2018. Apple is leading the charge, but it's clear there's still room in the market for competitors, as Samsung and Fitbit also did well.
Business

Apple loses battle to use Intel modems in Germany in latest clash with Qualcomm

Apple is following the Federal Trade Commission's lead and has sued Qualcomm for a massive $1 billion in the U.S., $145 million in China, and also in the U.K., claiming the company charged onerous royalties for its patented tech.
Computing

Breaking: Amazon won’t build headquarters in New York in face of opposition

Amazon has canceled plans for a New York City headquarters afer citizens, civic groups, and politicians pushed back on Governor Andrew Cuomo and New York City Mayor Bill de Blasio's exclamation of economic joy over Amazon's earlier…
Business

Cruise like Mick Jagger: Virgin Voyage’s new ship boasts RockStar Suites

Virgin Voyages, the new cruise company from the Virgin Group, is now taking reservations for the 2020 inaugural season. The ship's RockStar Suites are designed to help travelers feel like rock stars, going beyond the usual cruise luxuries.
Home Theater

Samsung will stop releasing new Blu-ray players in the U.S.

Samsung, the first company to produce a 4K Ultra HD Blu-ray player, is now exiting the Blu-ray market entirely in the U.S. The move comes after Oppo Digital also dropped out of the market last year.
Business

Alita: Battle Angel’s big opening weekend leads weak holiday box office

New box-office champion Alita: Battle Angel outperformed expectations with its big premiere and positive reviews from critics, but Presidents' Day weekend is still off to a slow start.