Starwood Data Breach: Clues in Marriott Hack Said to Implicate China

Advertisement
By Reuters | Updated: 6 December 2018 18:26 IST
Highlights
  • The hack began four years ago: Marriott
  • It exposed records of up to 500 million customers
  • Marriott acquired Starwood in 2016 for $13.6 billion

Photo Credit: Scott Olson/ Getty Images/ AFP

Hackers behind a massive breach at hotel group Marriott International left clues suggesting they were working for a Chinese government intelligence gathering operation, according to sources familiar with the matter.

Marriott said last week that a hack that began four years ago had exposed the records of up to 500 million customers in its Starwood hotels reservation system.

Private investigators looking into the breach have found hacking tools, techniques and procedures previously used in attacks attributed to Chinese hackers, said three sources who were not authorised to discuss the company's private probe into the attack.

Advertisement

That suggests that Chinese hackers may have been behind a campaign designed to collect information for use in Beijing's espionage efforts and not for financial gain, two of the sources said.

Advertisement

While China has emerged as the lead suspect in the case, the sources cautioned it was possible somebody else was behind the hack because other parties had access to the same hacking tools, some of which have previously been posted online.

Identifying the culprit is further complicated by the fact that investigators suspect multiple hacking groups may have simultaneously been inside Starwood's computer networks since 2014, said one of the sources.

Advertisement

The Chinese Embassy in Washington did not return requests for comment.

If investigators confirm that China was behind the attack, that could complicate already tense relations between Washington and Beijing, amid an ongoing tariff dispute and US accusations of Chinese espionage and the theft of trade secrets.

Advertisement

Marriott spokeswoman Connie Kim declined to comment, saying "We've got nothing to share," when asked about involvement of Chinese hackers.

Marriott disclosed the hack on Friday, prompting US and UK regulators to quickly launch probes into the case.

Compromised customer data included names, passport numbers, addresses, phone numbers, birth dates and email addresses. A small percentage of accounts included scrambled payment card data, said Kim.

Marriott acquired Starwood in 2016 for $13.6 billion (roughly Rs. 96,000 crores), including the Sheraton, Westin, W Hotels, St. Regis, Aloft, Le Meridien, Tribute, Four Points and Luxury Collection hotel brands, forming the world's largest hotel operator.

The hack began in 2014, shortly after an attack on the US government's Office of Personnel Management (OPM) compromised sensitive data on tens of millions of employees, including application forms for security clearances.

White House National Security advisor John Bolton recently told reporters he believed Beijing was behind the OPM hack, a claim first made by the United States in 2015.

Beijing has strongly denied those charges and also refuted charges that it was behind other hacks.

Former senior FBI official Robert Anderson told Reuters that the Marriott case looked similar to hacks that the Chinese government was conducting in 2014 as part of its intelligence operations.

"Think of the depth of knowledge they could now have about travel habits or who happened to be in a certain city at the same time as another person," said Anderson, who served as FBI executive assistant director until 2015.

"It fits with how the Chinese intelligence services think about things. It's all very long range," said Anderson, who was not involved in investigating the Marriott case and is now a principal with Chertoff Group.

Michael Sussmann, a former senior Department of Justice official for its computer crimes section, said that the long duration of the campaign was an indicator that the hackers were seeking data for intelligence and not information to use in cybercrime schemes.

"One clue pointing to a government attacker is the amount of time the intruders were working quietly inside the network," he said. "Patience is a virtue for spies, but not for criminals trying to steal credit card numbers."

FBI representatives could not immediately be reached for comment on the evidence linking the attack to China. A spokesperson said on Friday that the agency was looking into the attack, but declined to elaborate.

© Thomson Reuters 2018

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Starwood, Marriott, China
Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy S26 Series Could Launch on This Date
  2. Lava Agni 4 Will Be Launched on This Date
  3. Apple's iOS 26.1 May Launch on This Date, Followed By iOS 26.2 Beta Rollout
  4. Apple's Revamped Siri Could Be Equipped With This AI Model From Google
  5. You Might See New Product Displays at Apple Retail Stores On This Date
  6. One Piece: Into the Grand Line OTT Release Date Revealed: What You Need to Know
  7. OnePlus 15 to Get New OP Gaming Core Tech for Smoother Gameplay
  8. ISRO's 'Bahubali' Rocket Lifts India's Heaviest Satellite Yet
  1. Dude OTT Release Date: When and Where to Watch Pradeep Ranganathan Starrer Movie Online?
  2. Samsung Galaxy Unpacked 2026 Date Leaked; Samsung Galaxy S26 Series Expected to Launch: Report
  3. ISRO Launches India’s Heaviest CMS-03 GEO Communication Satellite
  4. Apple Said to Equip Revamped Siri With Gemini-Based AI Model Developed in Collaboration With Google
  5. Lava Agni 4 Launch Date Confirmed, Teased to Feature a MediaTek Dimensity Chip
  6. Apple’s iOS 26.1 Launch Expected This Week Followed By iOS 26.2 Beta Rollout: Report
  7. Another Launch? Apple Retail Stores to Reportedly Get New Product Displays Soon
  8. OnePlus Unveils OP Gaming Core Technology With HyperRendering and OP FPS Max for OnePlus 15 Series
  9. Hubble Observes Massive Stellar Eruption from EK Draconis, Hinting at Life’s Origins
  10. Scientists Detect Hidden Magnetic Waves That Could Explain the Sun’s Mysterious Heat
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.