Marriott Hotels has admitted to being hit by a data breach, its third since 2018.
According to the hotel chain, hackers were able to steal around 20GB of data, including internal documents, customer data, and potentially some credit card information.
According to Marriott, the majority of the data wasn’t sensitive, but it has notified around 300-400 individuals, as well as regulators and law enforcement.
The news was broken by privacy news site databreaches.net after people claiming to be the hackers messaged them.
The unnamed group (at their own insistence) say that they breached the hotel chain a month ago before exfiltrating the data. Analysis of files shared by the group suggest that the files came from BWI Airport Marriott in Maryland.
“Their security is very poor, there were no problems taking their data,” the hackers told databreaches. ” At least we didn’t get access to the whole database, but even the part that we took was full of the critical data.”
After databreaches contacted Marriott Hotels, they confirmed the data breach, though they claimed that the incident was less significant than the hackers portray it as.
It is currently unclear how the hackers were able to access the files. Marriott has said that the hackers used social engineering to get an associate at one hotel to give them access to their computer.
“We have no evidence that the threat actor had access beyond the files that were accessible to this one associate,” Marriott told databreaches.
Marriott claims they were aware of the data breach before the hackers contacted them and that the issue was contained within six hours.
While the hackers have contacted Marriott, there are no reports of the size of the ransom being demanded. Both sides claim that the hotel chain did not pay any money.
Marriott Hotels Data Breach
Marriott Hotels has been hit with two previous data breaches in the last four years.
In 2018, hackers accessed the company’s Starwood booking database in the US copying and encrypting information on around 500 million guests. This included names, mailing addresses, phone numbers, email addresses and passport numbers.
According to an investigation, the unauthorised parties had been accessing the database since 2014.
This resulted in a class action lawsuit, with claimants seeking $12.5 billion in damages. In the UK, the ICO said it would fine Marriott £99m for the data breach, eventually settling at £18.4m – one of the largest ever issued.
The second hack came in 2020, when 5.2 million guests’ personal details, including loyalty account information, contact details, were accessed. The breach saw unauthorised parties access the data using log-in details of two employees at a franchise property.
Recommended
- DIGIT Movers and Shakers | June 2022
- Online Safety Bill: What are Ofcom’s new powers to fight child abuse material?
- Skyscanner co-founder backs Edinburgh ‘work-surfing’ startup, Swurf
Commenting on the news, Dominic Trott, UK Head of Strategy at Orange Cyberdefense, believes that this breach, during which cybercriminals relied upon social engineering, highlights the need to protect against human error.
“The data breach suffered by Marriott Hotels highlights the ever-increasing issue of the insider threat, whether malicious or – as it would seem in this case – unwitting,” he said.
“The fact that cybercriminals are claiming to have accessed 20GB of data, including internal documents and the personal and payment information of 300-400 guests, is a stark reminder of the need for organisations to adopt a layered security strategy that defends against human error. Teaching employees how to recognise phishing attempts and detect malicious activity will ultimately enable them to access the security resources needed to stop cybercriminals in their tracks and carry out their own jobs safely and effectively.
“The need for defence-in-depth strategies that work to mitigate human error have never been more vital for businesses across all sectors, as the rise of flexi-working has resulted in work being a thing people do, rather than a place they go. Working in their own homes and other environments they’re comfortable in can cause staff to lower their defences and become more susceptible to social engineering attacks, as suffered by Marriott.
“To combat this, organisations should look to leverage solutions such as Zero Trust Network Access or SASE approaches, alongside giving employees the tools and education, they need to be a reliable first line of defence.”
Get the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





