Massive Marriott Data Breach Affects up to 500 Million Guests
This post contains references to products from one or more of our advertisers. We may receive compensation when you click on links to those products. Terms apply to the offers listed on this page. For an explanation of our Advertising Policy, visit this page.
Marriott International said Friday the data of up to 500 million of its guests has been stolen from its Starwood guest reservation database. The data breach is likely one of the largest ever in US history.
The hotel chain, which is the world’s largest, said in a release on Friday that it was first alerted to the hack in September after receiving notification from an internal security tool that there was an attempt to access customers’ data. The company started an investigation and learned that hackers have had access to Starwood guest database since 2014.
For four years, the hackers stole and encrypted customers’ personal information, creating their own database of Starwood guests’ data. It took Marriott until Nov. 19 to decode most of the breached information.
For about 327 million guests, the hackers absconded with “some combination of name, mailing address, phone number, email address, passport number, Starwood Preferred Guest (“SPG”) account information, date of birth, gender, arrival and departure information, reservation date, and communication preference,” Marriott said.
An undisclosed number of customers also had their payment card numbers and expiration dates breached. That information was encrypted in two parts, but the hotel chain said it can’t rule out that both were stolen and decoded.
For the remaining chunk of guests, the stolen information “was limited to name and sometimes other data such as mailing address, email address, or other information,” Marriott said.
“We are still investigating the situation so we don’t have a list of specific hotels. What we do know is that it only impacted Starwood brands,” Marriott spokesperson Jeff Flaherty told Reuters.
The hotel chain apologized to customers and has taken steps to address the security issues. Marriott is working with law enforcement on the breach. It also is providing affected customers with one free year of an information protection service, called WebWatcher. The company will start contacting affected customers by email on Friday.
Featured image by Roberto Machado Noa/LightRocket via Getty Images.
*This post has been updated with Marriott’s spokesperson’s comments.
Welcome to The Points Guy!
WELCOME OFFER: 60,000 Points
TPG'S BONUS VALUATION*: $1,200
CARD HIGHLIGHTS: 2X points on all travel and dining, points transferrable to over a dozen travel partners
*Bonus value is an estimated value calculated by TPG and not the card issuer. View our latest valuations here.
- Earn 60,000 bonus points after you spend $4,000 on purchases in the first 3 months from account opening. That's $750 toward travel when you redeem through Chase Ultimate Rewards®
- 2X points on travel and dining at restaurants worldwide, eligible delivery services, takeout and dining out & 1 point per dollar spent on all other purchases.
- Get 25% more value when you redeem for travel through Chase Ultimate Rewards®. For example, 60,000 points are worth $750 toward travel.
- Get unlimited deliveries with a $0 delivery fee and reduced service fees on orders over $12 for a minimum of one year on qualifying food purchases with DashPass, DoorDash's subscription service. Activate by 12/31/21.
- Earn 2x total points on up to $1,000 in grocery store purchases per month from November 1, 2020 to April 30, 2021. Includes eligible pick-up and delivery services.