Los Angeles Times

Marriott details data theft

Out of 25 million passport numbers stolen, 5.25 million were unencrypte­d.

- By Margot Roosevelt margot.roosevelt @latimes.com

Passport numbers of more than 25 million guests at the Starwood chain of hotels were stolen by hackers in November, Marriott announced Friday as the world’s largest hotel company comes to terms with the scope of the data breach.

The Bethesda, Md., company acknowledg­ed for the first time that 5.25 million of those passport numbers were unencrypte­d — or not coded to prevent unauthoriz­ed access. More than 20 million were encrypted. No evidence has yet surfaced that the hackers accessed the master encryption key needed to decrypt those passport numbers.

If the hackers were Chinese intelligen­ce agents, as security experts have suggested, the passport data could be particular­ly damaging because the breach would allow a foreign power to identify and track the movements of government and business travelers. China is reported to be assembling a database on people who could be useful in cyberwarfa­re.

The breach also included dates of birth and credit card numbers, as well as contact informatio­n such as mailing addresses and email addresses.

The incident involved about 383 million records of guests who made a reservatio­n at Starwood properties on or before Sept. 10, 2018, the company said. That’s fewer than the original figure of 500 million guests the company had announced as affected, but it still ranks the breach as one of the largest in history.

A 2013 data breach at Yahoo affected its 3 billion users, exposing names, birth dates, phone numbers and passwords. A 2017 hack at Equifax, the credit reporting giant, involved the Social Security and driver’s license numbers of about 145 million Americans.

Marriott said it had not yet determined how many of the 383 million records are duplicates involving the same guest.

The Starwood brands, which were acquired by Marriott in 2016, include W Hotels, St. Regis, Sheraton Hotels & Resorts, Westin Hotels & Resorts, Element Hotels, Aloft Hotels, the Luxury Collection, Tribute Portfolio, Le Meridien Hotels & Resorts, Four Points by Sheraton and Design Hotels. Timeshare properties such as Sheraton Vacation Club, Westin Vacation Club, the Luxury Collection Residence Club, St. Regis Residence Club and Vistana are also part of the chain.

Marriott establishe­d a dedicated website (https:// info.starwoodho­tels.com) and call center (877-2739481) to answer questions. Guests may enroll in web monitoring services free of charge for one year.

China has denied it was involved in the hack, which is under investigat­ion by the FBI.

 ?? Matt Rourke Associated Press ?? THE BREACH at Starwood, whose brands include Westin, involves 383 million records of guests who made reservatio­ns on or before Sept. 10.
Matt Rourke Associated Press THE BREACH at Starwood, whose brands include Westin, involves 383 million records of guests who made reservatio­ns on or before Sept. 10.

Newspapers in English

Newspapers from United States