The Marriott Hack: How to Protect Yourself

The international hotel chain, Marriott, has announced a massive data hack that impacts as many as 500 million customers who made a reservation at a Starwood hotel. Marriott acquired the Starwood hospitality group in September 2016, which operates numerous hotel brands including Sheraton, Westin, Aloft, and W Hotels. It is reported the enormous data breach started in 2014, before Marriott’s acquisition.
Currently it is thought that 327 million people had sensitive data stolen, such as, passport numbers, phone number, email address, date of birth, gender, trip and reservation information, and Starwood Preferred Guest account information. In addition is seems that around 170 million Marriott customers had their basic information stolen, including, names, address or email address. It has also been exposed that some credit card numbers were also stolen as part of the breach.
Breach response experts have stated the fact the attackers attackers had access for four years is likely to have made the breach worse. Time gives attackers the ability to chip away at defenses, or simply learn more about a system to understand where the valuable data is. It is also possible to hackers could have encrypted the stolen data as part of their exfiltration strategy. Hackers often use encryption as a tool to mask data and sneak it past a network’s “data loss prevention” defenses, which monitor for sensitive data in transit.
“If you made a reservation on or before September 10, 2018 at a Starwood property, information you provided may have been involved,” the company’s breach response page reads. The Marriott seem to be erring on the side of caution that all customers were affected before September this year. They have established a call center and breach notification website and are off offering enrollment in the identity monitoring service WebWatcher for one year to anyone who thinks they were impacted by the four-year network intrusion.
Marriott have responded to this incident with resources and information for victims, however a breach that lasted over four years is substantial. “They are still investigating this heavily and don’t know to what extent attackers had access—this could turn out to be much, much larger,” says David Kennedy, CEO of the penetration testing and incident response consultancy TrustedSec. “Four years is an eternity when it comes to breaches. If attackers had access for that long I would assume they had access to virtually everything.”