PCWorld (USA)

Here’s How

Here’s everything you need to know.

- BY MICHAEL SIMON

It’s been a couple of months since a major company unveiled a data breach that affected millions of people ( go.pcworld.com/tmdb), so it’s time for a new one. The Marriott hotel chain has announced ( go.pcworld.com/ dbsc) a major database breach that could affect anyone who stayed at its 6,700 worldwide Starwood hotel properties since 2014—up to 500 million people in total.

That’s a lot of people and a long stretch of time, so check out our FAQ:

WHAT HAPPENED?

Marriott says it received an alert from an internal security tool on September 8 warning of an attempt to access the Starwood guest reservatio­n database in the United States. In its investigat­ion of the incident, Marriott learned that an unauthoriz­ed party gained access to the company’s customer database and “copied and encrypted informatio­n, and took steps toward removing it.”

HOW DID THE HACKERS GET IN?

Marriott isn’t being totally clear here, but it appears as though this wasn’t the usual exploit of a vulnerabil­ity. Rather, someone without the proper credential­s was able to access the Marriott reservatio­n database to make a duplicate encrypted copy of customer informatio­n, which was then presumably taken outside the system.

HOW FAR BACK DOES THE BREACH GO?

Marriott says the unauthoriz­ed access goes back to 2014.

WHY WASN’T MARRIOTT ALERTED SOONER?

Also unclear, but perhaps the unauthoriz­ed party only recently started accessing the system. Or possibly Marriott recently installed new security software that was able to detect the access.

WHY ARE WE JUST HEARING ABOUT THIS NOW?

Marriott says it was only able to decrypt the files on November 19, and is still working to uncover the scope of the breach.

WHAT WAS STOLEN?

Marriott is still sorting through the data it was able to recover, but for most customers, the following data may have been stolen: name, mailing address, phone number, email address, passport number, Starwood Preferred Guest (“SPG”) account informatio­n, date of birth, gender, and arrival and departure informatio­n, along with reservatio­n dates and communicat­ion preference­s.

SHOULD I CHANGE MY PASSWORD?

Marriott hasn’t said whether any

accounts were accessed or passwords stolen, but it certainly can’t hurt. But this was a breach of the company’s internal database of hotel guests, not online accounts.

Password managers make it easy to create strong, unique passwords for every site you visit. If you aren’t using one yet, our guide to the best password managers can help you pick a great one ( go.pcworld.com/pwmn).

WHAT ABOUT CREDIT CARD INFORMATIO­N?

For some users, Marriott says payment card numbers and payment card expiration dates were included in the stolen data, but card numbers were encrypted using Advanced Encryption Standard encryption (AES-128).

SO MY CREDIT CARD IS SAFE?

Possibly not. As Marriott explains: “There are two components needed to decrypt the payment card numbers, and at this point, Marriott has not been able to rule out the possibilit­y that both were taken.”

WHAT ABOUT MY SPG POINTS?

Marriott says there is no evidence that any loyalty points were obtained, but you should check your account for any suspicious activity.

HAS THE BREACH BEEN STOPPED?

Presumably, but Marriott doesn’t explicitly say whether the unauthoriz­ed access has been shut down. However, the chain is working with law enforcemen­t agencies and regulatory authoritie­s, so the likelihood of a continued breach is extremely low.

WHAT IS MARRIOTT DOING TO STOP FUTURE BREACHES?

Again, it’s not totally clear if the hacker exploited a vulnerabil­ity or merely used an unauthoriz­ed password, but Marriott says it is devoting the resources necessary to phase out Starwood systems and accelerate the ongoing security enhancemen­ts to our network.

HOW DO I KNOW IF MY DATA WAS ACCESSED?

Marriott began sending emails on a rolling basis on November 30 to affected guests, so be sure to check your email, particular­ly your spam folder, to see if you’ve received one.

WHAT CAN I DO IF I AM AFFECTED?

Marriott has set up a dedicated call center to answer any questions you may have. U.S. Customers can call 877-273-9481 seven days a week to reach a representa­tive.

SHOULD I CANCEL MY CREDIT CARD?

That is not a bad idea. If you know the credit card or cards that are on file with Marriott or Starwood hotels, canceling them now is the best way prevent any future malfeasanc­e.

WHAT ELSE CAN I DO?

Marriott is providing all guests in the U.S., Canada, and the UK with the opportunit­y to enroll in Kroll’s Web Watcher Monitoring Service ( go.pcworld.com/krll), which tracks sites where personal informatio­n is shared and alerts you if evidence of your personal informatio­n is found.

Our guide to what to do after a data breach ( go.pcworld.com/5dtb) can help you minimize your exposure to any pilfered informatio­n. Good luck.

 ??  ??
 ??  ??
 ??  ??
 ??  ??
 ??  ??

Newspapers in English

Newspapers from Australia