March 20, 2019

Five million unencrypted passport numbers among Marriott hack

06 January 2019, 10:59 | Joann Bryant

Hackers stole more than 300 million records from Marriott in 2014. Igor Golovniov SOPA Images LightRocket via Getty Images

Marriott International Hospitality company logo seen

The company disclosed on Nov 30 that it had discovered its Starwood hotels reservation database had been hacked over a four-year period in one of the largest breaches in history. Starwood branded timeshare properties (Sheraton Vacation Club, Westin Vacation Club, The Luxury Collection Residence Club, St. Regis Residence Club, and Vistana) are also included.

There were about 8.6 million encrypted credit card numbers stolen in the breach as well, Marriott said.

While the passport numbers would be considered sensitive personal information that should not be made public, the numbers and names of guests alone would not be enough for a criminal to create a forged passport. Marriott will soon enable customers to access "resources" to see whether their passport numbers were exposed.

In addition to passport data, which some theorise could be used by malign actors to track worldwide travellers, approximately 345,000 unexpired payment cards were stored by the company.

While downsizing the estimate of how many guests were impacted by the historic breach of its hotel reservation system, Marriott International on Friday announced that roughly 5.25 million unencrypted passport numbers are now among the sensitive data illegally obtained by hackers unknown.

The bad news is that the company confirmed that more than five million unencrypted passport numbers were stolen, on top of the more than 20 million encrypted passport numbers.

"There is no evidence that the unauthorized third party accessed either of the components needed to decrypt the encrypted payment card numbers", Marriott said in its statement.

Finally, Marriott now believes around 8.6 million encrypted payment cards were impacted by the data breach. The website lists phone numbers to reach the company's dedicated call center and includes information about the process to be followed if guests believe that they have experienced fraud as a result of their passport numbers being involved in this incident. Regardless, Marriott says there isn't any evidence that the hackers acquired the tools needed to decrypted the card info.

A small number of payment cards - "fewer than 2,000" - may have been stored separately and in an unencrypted format, according to Marriott.

The company also has updated estimates about how many passport numbers and how many payment methods were actually compromised. The call center is open seven days a week and is available in multiple languages.

Marriott said in its Friday update that it has "completed the phase out" of Starwood's reservation database and now runs guest bookings through its Marriott database, which was not affected by the breach.

Other News

Trending Now

Elizabeth Warren Brings 2020 Bid Message To Iowa
She was the daughter of a janitor who lost work after a heart attack, forcing her mother to take a minimum wage job. I am not a citizen of a tribe. "Tribal citizenship is very different from ancestry", she added.

Newly Sworn-In Rep. Tlaib: 'We're Gonna Impeach the Motherf***er'
Tlaib, you've probably heard by now, talked at an event this week about how Democrats are going to " impeach the motherfucker ". Speaking to reporters in the Rose Garden, Trump said Friday that he thought Tlaib's comments were "disgraceful".

Man, 20, charged with capital murder in girl’s death in Houston
A suspect had pulled alongside a vehicle Jazmine Barnes was sitting in outside a Walmart and opened fire. Hundreds of people gathered at a rally Saturday afternoon for the girl near where the shooting happened.

Arsenal considering swap deal approach with Juventus for Mehdi Benatia
Emery previously worked with Suarez when the youngster arrived at his Sevilla team on loan for the 2014/15 season. Benatia could potentially be used as part of the deal to take midfielder Aaron Ramsey to Juventus .

Shanahan takes Pentagon helm as Trump blasts Mattis
But Trump, who was miffed by the media coverage Mattis' letter received, ordered him to leave to the Pentagon by January 1. On Wednesday, Trump downplayed Mattis' importance to his national security team and his administration more broadly.

Brazil navy uneasy with Bolsonaro's openness to USA base: supply
Brazil is set to become the third nation-after the US and Guatemala-to officially recognize Jerusalem as the capital of Israel. A little-known legislator before the election season, Bolsonaro won on a platform of fighting crime and corruption.

Philadelphia Phillies Sign David Robertson
Robertson appeared in 69 games for the Yankees last season, going 8-3 with a 3.23 ERA and five saves. The Yankees have now said goodbye to David Robertson for the second time in the last four years.

Ronaldo celebrates New Year at UAE
Special awards such as the Coach Career Award - presented by Du - and several Player Career Awards will also be made on the night. Ronaldo, 33, moved from Real Madrid to Italian giant Juventus for a fee of €100 million ($170 million) in July previous year .

LG Is Bringing Giant 8K TVs To CES 2019
The company revealed the new TVs ahead of next week's CES 2019 exposition, where competition will likely showcase other 8K TVs. LG's 2018 TVs introduced the α (Alpha) 9 intelligent processor and ThinQ AI, but all of that is getting a big update in 2019.

Police Release Sketch Of Man Wanted In Slaying Of Child In Texas
Activist Shaun King tweeted an updated description of the suspect that he said a confirmed eyewitness sent to him. Her mother, LaPorsha Washington , 30, and one of Jazmine's sisters were injured in the apparently random attack.