Skip to main content

Marriott asking guests for data to see if they were victims of the Starwood hack

Marriott is now offering an easy way to confirm if your personal details were stolen in the massive Starwood hack that was revealed by the hotel giant in November 2018.

Guests who suspect their data may have been involved are being asked to fill out an online form, which will allow the company to make an accurate check. But the company is unable to say how long it will take to respond, saying only that it will reply “as soon as reasonably practicable and consistent with applicable law.”

Yes, it is rather ironic that you have to submit personal data to find out if your personal data was stolen. But if you feel you can still trust the company to handle your data in a secure manner, then the process has the potential to offer peace of mind about whether or not your details were caught up in the hack.

The damaging security breach, which was first reported in November last year, affected accounts that had used Starwood’s guest reservation database between 2014 and September 10, 2018.

The hack shocked many not only for its size, but also for the wide variety of data taken. The initial announcement suggested as many as 500 million guests were involved, with lifted information including a combination of name, address, date of birth, gender, phone number, email address, passport number, Starwood Preferred Guest account information, arrival and departure information, reservation date, and encrypted payment card numbers.

Having now removed duplicate records, Marriott announced in recent days that it’s been able to identify “approximately 383 million records as the upper boundary for the total number of guest records that were involved in the incident.”

It added that this doesn’t necessarily mean that 383 million unique guests were involved, “as in many instances, there appear to be multiple records for the same guest.”

What it can now say, with a fair degree of certainty, is that the stolen records included around 8.6 million unique payment card numbers, all of which were encrypted. Some 5.25 million unique unencrypted passport numbers and approximately 20.3 million encrypted passport numbers were also nabbed in the breach.

For the latest information on the hack, visit Marriott’s special webpage. Mention of the online form can be found at the top of the FAQs, under the question: “Was my information involved in the incident?”

Marriott acquired Starwood in September 2016 in a deal worth around $13.6 billion. Starwood brands include the likes of Le Meridien, Sheraton, St. Regis, Westin, and W Hotels, among others.

Trevor Mogg
Contributing Editor
Not so many moons ago, Trevor moved from one tea-loving island nation that drives on the left (Britain) to another (Japan)…
Here’s the major mistake one LAPSUS$ hacking victim made
A digital depiction of a laptop being hacked by a hacker.

Digital security authentication company Okta raised eyebrows when it confirmed it was targeted by Microsoft and Nvidia hackers, LAPSUS$, around two months after the breach occurred.

The wait between the initial period of the cyber security incident and the official acknowledgment of the hack caused serious concern among security researchers and the technology community. Now, Okta has published an FAQ regarding the situation where it admits the firm made a mistake.

Read more
Tesla factories’ security cameras caught up in wider hack
Tesla Gigafactory

A Silicon Valley startup offering cloud-based security camera services has had its systems breached in an attack that gave hackers access to numerous live feeds, some of them coming from Tesla factories.

Verkada, which launched in 2016, had around 150,000 of its cameras hacked, with many of the devices installed in hospitals, schools, police departments, prisons, and companies that besides Tesla also included software provider Cloudflare, according to a Bloomberg report on Tuesday, March 9.

Read more
Twitter confirms DMs were accessed in last week’s major hack
Twitter logo.

Twitter has revealed more information about the major hack involving a Bitcoin scam that targeted dozens of high-profile accounts on its service on Wednesday, July 15.

The company said in a tweet on Wednesday, July 22, that following a complete review of all of the impacted  Twitter accounts, it believes that “for up to 36 of the 130 targeted accounts, the attackers accessed the DM [direct message] inbox, including 1 elected official in the Netherlands.” Twitter did not name the elected official.

Read more