Massive Marriott Data Breach Exposes Personal Data of 500 Million People Over Four Years
*By Carlo Versano and Chloe Aiello*
Marriott's reservation system for its Starwood hotel properties has been breached since 2014, exposing the sensitive personal data of up to 500 million guests over more than four years, the world's largest hotel chain [revealed](http://news.marriott.com/2018/11/marriott-announces-starwood-guest-reservation-database-security-incident/) Friday. New York Attorney General Barbara Underwood immediately announced an investigation into the attack.
The hacked personal data included passport numbers, credit card information, dates of birth, and phone numbers. The breach amounts to the largest corporate data hack since 2013, when Yahoo!'s entire user base of three billion people was exposed. But a hotel database would likely hold more sensitive information, meaning a hack of this scale from the world's leading hotel chain could be the most significant yet.
Rikesh Thapa, the CTO and co-founder of blockchain technology company Blockparty, said he assumes bad actors wasted no time in securing the information, so people who suspect their data was compromised need to be vigilant.
"I would bet that it was on the black market already," Thapa told Cheddar on Friday.
The breach of Equifax's database last year exposed social security numbers and credit cards of about 200,000 people in the U.S., a fraction of the number of customers who may be impacted after Marriott's disclosure.
Marriott acquired Starwood in 2015 for $13 billion, folding brands like Westin, Sheraton, W, and St. Regis into the Marriott portfolio. The company said any reservation between 2014 and Sept. 10, 2018 at any Starwood properties worldwide was affected.
Marriott President Arne Sorneson apologized in a statement, saying: "We are doing everything we can to support our guests, and using lessons learned to be better moving forward.” The company set up a [website](info.starwoodhotels.com) to provide more information about the breach. It also said it was working with law enforcement to identify the hackers. Marriott did not say why it took four years to identify that its systems had been penetrated.
The delay suggests the company was technologically far behind, Thapa said.
The hack "should never have happened if Marriott or companies like Marriott paid attention to technological advancements and made sure that their machines were up to date," Thapa said.
"This hack supposedly happened in 2014 ... which means they had not upgraded their system for probably more than four years, so this person was siphoning data, or group was siphoning data, since then."
As for what's next for Marriott, Thapa said he expects "they are going to get fined like crazy" for violating Europe's General Data Protection Regulation.
"Whether or not they survive it, they're definitely going to be calling up a lot of security professionals trying to upgrade their security system ー I would hope so," he said.
Ted Rossman, an analyst for CreditCards.com, took a rosier view than many analysts Friday. "I don't know if there's anything truly new here," he said, predicting more corporate hacks will follow. "We as consumers need to assume that our data is out there."
He pointed out a new law that makes it free for consumers to freeze, and then "thaw," their credit ー a process that used to cost $30 in some states and involve rounds of phone calls. Now it can be done via the websites of the three main credit agencies. Credit freezing is the "best line of defense we have," according to Rossman.
Shares of Marriott plummeted 5 percent on news of the hack.
Chris Williamson, Chief Business Economist at S&P Global, breaks down September’s CPI print and inflation trends, explaining what it means for markets.
A big-screen adaptation of the anime “Chainsaw Man” has topped the North American box office, beating a Springsteen biopic and “Black Phone 2.” The movie earned $17.25 million in the U.S. and Canada this weekend. “Black Phone 2” fell to second place with $13 million. Two new releases, the rom-com “Regretting You” and “Springsteen — Deliver Me From Nowhere,” earned $12.85 million and $9.1 million, respectively. “Chainsaw Man – The Movie: Reze Arc” is based on the manga series about a demon hunter. It's another win for Sony-owned Crunchyroll, which also released a “Demon Slayer” film last month that debuted to a record $70 million.
The Federal Aviation Administration says flights departing for Los Angeles International Airport were halted briefly due to a staffing shortage at a Southern California air traffic facility. The FAA issued a temporary ground stop at one of the world’s busiest airports on Sunday morning soon after U.S. Transportation Secretary Sean Duffy predicted that travelers would see more flights delayed as the nation’s air traffic controllers work without pay during the federal government shutdown. The hold on planes taking off for LAX lasted an hour and 45 minutes and didn't appear to cause continued problems. The FAA said staffing shortages also delayed planes headed to Washington, Chicago and Newark, New Jersey on Sunday.
Boeing workers at three Midwest plants where military aircraft and weapons are developed have voted to reject the company’s latest contract offer and to continue a strike that started almost three months ago. The strike by about 3,200 machinists at the plants in the Missouri cities of St. Louis and St. Charles, and in Mascoutah, Illinois, is smaller in scale than a walkout last year by 33,000 Boeing workers who assemble commercial jetliners. The president of the International Association of Machinists says Sunday's outcome shows Boeing hasn't adequately addressed wages and retirement benefits. Boeing says Sunday's vote was close with 51% of union members opposing the revised offer.
The stunning indictment that led to the arrest of more than 30 people — including Miami Heat guard Terry Rozier and other NBA figures — has drawn new scrutiny of the booming business of sports betting in the U.S. The multibillion-dollar industry has made it easy for sports fans — and even some players — to wager on everything from the outcome of games to that of a single play with just a few taps of a cellphone. But regulating the rapidly-growing industry has proven to be a challenge. Professional sports leagues’ own role in promoting gambling has also raised eyebrows.
Tesla, the car company run by Elon Musk, reported Wednesday that it sold more vehicles in the past three months after boycotts hit hard earlier this year, but profits still fell sharply. Third-quarter earnings fell to $1.4 billion, from $2.2 billion a year earlier. Excluding charges, per share profit of 50 cents came in below analysts' estimate. Tesla shares fell 3.5% in after-hours trading. Musk said the company's robotaxi service, which is available in Austin, Texas, and San Francisco, will roll out to as many as 10 other metro areas by the end of the year.