Marriott Says Up to 500 Million Customers Impacted by Starwood Hack

Advertisement
By Reuters | Updated: 1 December 2018 14:45 IST

Marriott International Inc said on Friday that hackers accessed up to 500 million customer records in its Starwood Hotels reservation system in an attack that began four years ago, exposing data including passport numbers and payment cards.

Shares were down 5.7 percent in late afternoon trade on news of the hack, one of the largest in history, which prompted regulators in Britain and at least five U.S. states to launch investigations.

The Federal Bureau of Investigation said it was looking into the attack on Starwood, whose brands include Sheraton, St. Regis, W and Westin hotels. It advised affected customers to check for identity fraud and report it to the bureau's Internet Crime Complaint Center.

Advertisement

The hack began in 2014, a year before Marriott offered to buy Starwood to create the world's largest hotel operator. The $13.6 billion deal closed in September 2016.

Advertisement

Some 327 million customer records containing information including passport details, birthdates, addresses, phone numbers and email addresses were exposed, according to the company.

The hackers also accessed payment card data for an undisclosed number of customers, the company said.

Advertisement

"What makes this serious is the number of people involved, the intimacy of the data that was taken and the long delay between the breach and discovery," said Mark Rasch, a former U.S. federal cyber crimes prosecutor.

Some customers complained to Marriott on Twitter, where Starwood was among the top trending U.S. topics. They used terms including "duped," "angry" and "merger disaster" to express frustration over the incident.

Advertisement

Attorneys filed a lawsuit in a Maryland federal court within hours of the disclosure which seeks class-action status for customers whose data was exposed in the breach.

The complaint accuses Marriott of negligence as well as deceptive and unfair trade practices and sought unspecified financial compensation for harm caused by exposure of their data.

The company said on its website that it learned of the breach on Sept. 8 when an internal security tool sent an alert about suspicious activity.

"We fell short of what our guests deserve," Marriott Chief Executive Arne Sorenson said in a statement.

Attorneys general in Connecticut, Illinois, Massachusetts, New York and Pennsylvania said they would investigate the attack, as did the UK's Information Commissioner's Office.

"The public deserves to know how this happened," Massachusetts Attorney General Maura Healey said in a statement.

Company representatives could not be reached to comment on the lawsuit, government investigations or to explain why it had taken so long to uncover and disclose the hack.

Marriott said on its website that it would inform affected guests about the breach starting on Friday, and that it had reported it to law enforcement and regulatory authorities.

The breach appeared to be the second-largest on record, based on records compromised, after one at Yahoo in 2013 that exposed all of its 3 billion user accounts. That incident cost $47 million in litigation expenses and prompted Verizon Communications Inc to cut $350 million off the price it paid when it acquired most of Yahoo.

Marriott said it was too early to estimate the financial impact of the breach, though it would not affect its long-term financial health. The hotel chain said it was working with its insurance carriers to assess coverage.

Baird Equity Research said in a note to clients that breach-related costs, including legal fees, technical expenses and increased security, could force Marriott to delay the roll out of a new customer loyalty program planned for early 2019.

"Investor sentiment toward Marriott could remain somewhat negative in the near term until this security incident is fully resolved and its true financial impact is learned," Baird said.

Retailers Target Corp and Home Depot Inc each incurred costs of about $200 million after massive payment-card breaches in 2013 and 2014.

The Hyatt breach highlights the need for companies to pay close attention on cyber security when making acquisitions.

"Understanding the cybersecurity posture of an investment is critical to assessing the value of the investment and considering reputational, financial, and legal harm that could befall the company," said Jake Olcott, a vice president with cybersecurity firm BitSight.

© Thomson Reuters 2018

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Marriot, Starwood
Advertisement
Popular Mobile Brands
  1. Xiaomi 17 Ultra Finally Arrives in India at This Price
  2. Canva's AI-Powered Magic Layers Turns Images Into Editable Designs
  3. Samsung Galaxy A57 Renders Leak Online Again; Launch Expected Soon
  4. Vivo Y51 Pro 5G Launched With 7,200mAh Battery at This Price in India
  5. Poco X8 Pro Series Confirmed to Launch in India With This Battery
  6. Xiaomi 17 Launched in India With Snapdragon 8 Elite Gen 5, Leica Cameras
  7. Crimson Desert Specs Revealed: Here's How the Game Will Run on PS5, Xbox
  8. DxOMark Ranks iPhone 17 Pro Above Galaxy S26 Ultra in Camera Performance
  9. Realme P4 Lite 5G Confirmed to Launch in India Soon
  1. James Webb Telescope Captures Rare Infrared Footprints of Io and Ganymede Inside Jupiter’s Auroras
  2. WhatsApp Adds Support for Parent-Managed Accounts With Stricter Controls for Children Under 13
  3. Crimson Desert PC and Console Specs Revealed: Here's How the Game Will Run on PS5 and Xbox Series S/X
  4. Perplexity Ordered to Stop Deploying Shopping AI Agents on Amazon: Report
  5. Sonos Play and Sonos Era 100 SL Launched With Wi-Fi 6 Connectivity, AirPlay 2 Support: Price, Features
  6. Oppo Find N6 Colourways, Storage Variants Revealed as Company Teases Crease-Free Display's Components
  7. Canva’s New AI-Powered Magic Layers Feature Turns Images Into Editable Designs
  8. Tokenised Real-World Assets See 66 Percent Jump in 2026, DeFiLlama Data Shows
  9. The Society Season 2 OTT Release: Where to Watch Munawar Faruqui and Shreya Kalra’s Reality Survival Series?
  10. YouTube’s Likeness Detection Tool Expanded to Government Officials and Journalists
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.