9 ms·
Marriott hack hits 500M Starwood guests
- koboll 8y ago>"We deeply regret this incident happened," the company said in a statement. This is peak non-apology apology.
- duxup 8y agoWell I'm sure they regret it... it's very inconvenient for them.
- ourcat 8y agoNote: This has affected Marriott's "Starwood" division. Starwood's hotel brands include W Hotels, Sheraton, Le Méridien and Four Points by Sheraton. Marriott-branded hotels use a separate reservation system on a different network.
- pgrote 8y agoOdd. It looks like the intrusion could be the cause of the hurried merge. https://www.wsj.com/articles/inside-the-marriott-starwood-loyalty-program-turbulence-1543416010 https://www.wsj.com/articles/inside-the-marriott-starwood-lo... According to the article the systems were merged 3 months ago. "The company resolved one major issue involving elite-night credits earned from credit card spending just last week, more than three months after the integration. That problem left many members in limbo, unsure of how close they were to hitting elite-level thresholds before year’s end." The intrusion was detected on Starwood's system in September according to the BBC article. "On September 8, 2018, Marriott received an alert from an internal security tool regarding an attempt to access the Starwood guest reservation database. Marriott quickly engaged leading security experts to help determine what occurred. Marriott learned during the investigation that there had been unauthorized access to the Starwood network since 2014. Marriott recently discovered that an unauthorized party had copied and encrypted information, and took steps towards removing it. On November 19, 2018, Marriott was able to decrypt the information and determined that the contents were from the Starwood guest reservation database."
- sailfast 8y agoThis sounds more like Marriott having better monitoring and once the DBs got merged they figured out somebody had been in the Starwood network for four years.
- bpp 8y agoAssuming poor security practices is the new assumption of monetary debt from a merger. One wonders what it will take to get companies to take auditing potential acquisitions' security practices in greater depth.
- Aloha 8y agoMerged isnt the right word - everyone was migrated to the legacy Marriott System.
- tyingq 8y agoStarwood's reservation system is something called "Valhalla". There's some background info here: https://www.hospitalitynet.org/opinion/4078764.html https://www.hospitalitynet.org/opinion/4078764.html and here: https://www.infoworld.com/article/2673726/operating-systems/starwood-aims-for-enterprise-valhalla.html https://www.infoworld.com/article/2673726/operating-systems/...
- trollied 8y ago"It said some records also included encrypted payment card information, but it could not rule out the possibility that the encryption keys had also been stolen." Oh dear.
- flavor8 8y ago~"We encrypt sensitive data at rest. And we store decryption keys on our user facing app servers so that apps can decrypt the data. Cool, right?"
- londons_explore 8y agoLets be honest, all reversible encryption schemes are some version of this...
- willvarfar 8y agoI'm not quite sure whether irreversible encryption is a thing in this context (its sometimes used to talk about e.g. password storage, but I think that's a very different use-case), so I'll sally in with an interesting tangent: https://en.wikipedia.org/wiki/Homomorphic_encryption https://en.wikipedia.org/wiki/Homomorphic_encryption Homomorphic encryption is a form of encryption that allows computation on ciphertexts, generating an encrypted result which, when decrypted, matches the result of the operations as if they had been performed on the plaintext. Homomorphic encryption can be used for secure outsourced computation ...
- brianberns 8y agoThat's interesting, but how do you prevent bad guys from "generating an encrypted result" that you don't want?
- heavenlyblue 8y agoIf the variant of the homomorphic encryption you are using is secure, then the bad guys can not generate specifically crafted cyphertext that would decrypt into the result they specifically want.
- dopamean 8y agoWhy on earth would they hold onto passport numbers? The amount of data companies hold onto is ridiculous. It can't all be necessary.
- dagw 8y agoLots of countries legally require that hotels collect and store passport details of foreign guests.
- willvarfar 8y agoIn many countries hotels are required by law to keep passport numbers of foreign guests. In the US there is, apparently, no federal law; however, it is often part of state law: https://travel.stackexchange.com/questions/76012/laws-requiring-identification-at-hotel-check-in https://travel.stackexchange.com/questions/76012/laws-requir... In many more countries hotels do it despite it not being required; they just do it to assist law enforcement agencies. And doubtless they like to keep the data themselves as an effective way to track and mine guests across multiple visits.
- deleted 8y ago[deleted]
- lsiunsuex 8y agoIt's like you need to keep a running diary of every single service you've used / every single place you've been so when something happens like this, maybe you can find out if you actually used that service or visited that place. I think I stayed at a Starwood 2 years ago in PA? But I don't remember if it was a Starwood or some other Marriott brand.
- qrbLPHiKpiux 8y agoI have a domain I use with Fastmail that when I use a service or website, if I need to register an email it's always: service or websiteName @ mydomain.com Doesn't cover all, but at least it's something...
- noja 8y agoCombined with a unique string, or just the bare name?
- qrbLPHiKpiux 8y agoThe one I have for here is hn@
- kaybe 8y agoFor not-so-important things, I can recommend mailhero: https://mailhero.io/ https://mailhero.io/ It's free, just give it a try!
- guitarbill 8y agoThis was one of the unexpected perks of moving to FastMail, which has been an awesome experience so far. I'd highly recommend it. You can do something similar in Gmail with `name+label@gmail.com`, but a shocking number of sites ban valid characters from email addresses (intentionally?). That and a lot of clients have super annoying alias settings, so replying to such an email is a royal pain.
- laumars 8y agoThis is why I do my upmost to avoid entering payment details on as many sites as I can. Unique passwords (and usernames too if that is an option) are easy to manage via lastpass et al. Unique email addresses are harder but you might be able to fudge something using the "+ label" feature. But the real challenge is payment details. I'd be quite happy using Paypal everywhere if that were possible as then I'd only need to worry about Paypal getting hacked. What I really don't like is shopping sites that require me to enter my payment details (or worse: require me to save payment details). I avoid those places in almost all cases.
- keehun 8y agoHere's a link to the official Marriott release, FWIW: http://news.marriott.com/2018/11/marriott-announces-starwood-guest-reservation-database-security-incident/ http://news.marriott.com/2018/11/marriott-announces-starwood...
- noja 8y ago"We cannot find any evidence that the stolen information has been misused" - says every company ever, as if that means anything. I give it 24 hours.
- raisedbyninjas 8y agoThe only logical conclusion is the data must have been stolen as an academic exercise.
- bduerst 8y agoHow lucky Marriott is, to have some good Samaritans to stress-test their security without the intention to misuse their user data.
- ken 8y agoThe NYTimes article about this incident says: > “Usually when stolen data doesn’t appear, it’s a state actor collecting it for intelligence purposes,” said James A. Lewis, a cybersecurity expert at the Center for Strategic Studies in Washington.
- YetAnotherNick 8y agoNot to downplay it but my email shows 3 breaches in haveibeenpwned.com, and I haven't had any problem till now, apart from probably more emails in spam folder.
- geggam 8y agoPrivacy is dead. Long live... ?
- brootstrap 8y agoGetting constantly hacked from all angles. FB AMZN GOOG AAPL are always listening to us thru devices. Mega corps build systems that leave sensitive data exposed to the public web. I'm curious to see what actually caused this hack. I wonder if they used mongo db with default settings lol.
- Latteland 8y agoI think the vast majority of these hacks come from some random office working clicking on a doc in an email and opening it up in a microsoft app, on microsoft windows. we've never really blocked that up yet. I don't see it coming because someone hacked the backend of apple, google or amazon. who knows about facebook.
- code4tee 8y agoThat’s quite a lot of gasoline being thrown on the whole train wreck that is the Starwood integration.
- Aloha 8y agoI wouldnt call it a wreck, probably 80% of members transitioned without any real problem. For some though, its been awful.
- TekMol 8y agoIt said some records also included encrypted payment card information, but it could not rule out the possibility that the encryption keys had also been stolen. Why did the world end up with a pull-system for payments? Why do I have to give out my credit card number and enable the other side to pull arbitrary amounts as often as they like? This is one of several things crypto currencies got right. You pay by pushing money to the other side.
- ryanlol 8y agoWhy do you care if your credit card number is compromised?
- TekMol 8y agoBecause last time that happened it was a big hassle. I had to: * Do a phone call * Fill out paperwork * Wait for a new card to arrive * Go through all services I use the card for and change it
- 706f6f70 8y agoTo whom shall I address the invoice for my time though?
- maccard 8y agoHave to say, last time my card was replaced for fraud, it was easy. Bank noticed it and called me, cancelled my card, sent a new one (had it 2 days later), and I had to update the payment information on a handful of websites/services (amazon, google pay, paypal covered most of my bases). It had the nice side effect of emailing me telling me that pyament for X service had been declined, and made me think twice about renewing it (netflix)
- TekMol 8y agoSounds we have had similar experiences. But different definitions of 'easy'. Also, what if you had currently been somewhere else around the globe. How would you gotten the new card?
- PunchTornado 8y agoI guess without GDPR there wouldn't have been a push for these companies to notify of breaches so early. We could have found out about it next year. Also given the potential penalties, probably companies will now start to invest more in proper IT systems.
- ramblerman 8y agoWas that part of GDPR? I know they have to hold the minimum amount of information needed, and inform you clearly what they know. But weren't they always required to announce a breach?
- robin_reala 8y agoGDPR has a specific 72 hour time limit on breach announcements: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/personal-data-breaches/ https://ico.org.uk/for-organisations/guide-to-the-general-da... In this case, they discovered the breach on September 8, 2018, and announced it on 30th November, 2018. That’s 1,464 hours, a little bit more than 72.
- PunchTornado 8y agohmm, they say they reported it to the regulatory authorities at the time of the incident. So i guess they are safe on that one.
- robin_reala 8y agoAh, true. I hadn’t internalised that you only have to announce it publically in cases with “a high risk of adversely affecting individuals’ rights and freedoms”.
- pbhjpbhj 8y agoAFAICT companies can still hold all your information /if you consent/ but can't withold service if you don't consent unless they can prove that information is required for provision of the service. So, can they show passport number is required in my jurisdiction, if not then I can have a room without providing it.
- aaaaaaaaaab 8y agoI hope they at least hashed the credit card numbers ( ͡° ͜ʖ ͡°)
- tgtweak 8y agoWishful thinking, they encrypted them so they could conveniently be recovered.
- sneak 8y agoI find this to be justification in carrying a fake ID and issuing a credit card from my corporate line of credit in that cover name for use when renting hotel rooms. Every time a private organization demands your government ID to do business, assume that this will happen eventually. Airlines and hotels immediately come to mind, but I am sure there are lots of others. I'm not sure that air travel with a fake ID is viable due to Secure Flight, however. Also, as rental car insurance interfaces (potentially) with a police report/government ID, I am not sure I will rent cars in the future. When it comes to places you regularly or habitually sleep, this could mean direct physical danger to you, depending on circumstance. Protect yourself.
- deleted 8y ago[deleted]
- SketchySeaBeast 8y ago> When it comes to places you regularly or habitually sleep, this could mean direct physical danger to you, depending on circumstance. Sorry, what are you saying here? That the online identity thieves will come to your house?
- sneak 8y agoThat people looking to extort, blackmail, or kidnap you or your family can now tail you from the hotels you usually/habitually frequent during conferences you consistently attend. It lets them predict your future location so that physical surveillance or ambush can be prepared.
- SketchySeaBeast 8y agoI doubt that's going to be the result. I doubt that anyone is in any way that important. It's going to be financial / identity fraud, there's no reason for the thief to ever see your face.
- sneak 8y ago
- visarga 8y ago... and ... nothing will happen to Marriott.
- CaptainZapp 8y agoGreat! My last stay at a Starwood property was in January 2016 at the Bangkok LeMeridien. Not that they would bother to set up a call center number for Switzerland. Do they really expect me to call internationally at my expense to then hang in a loop for an hour or so? On the plus side: Nothing bad happened since then. Nevertheless I'm not impressed.
- bryanrasmussen 8y agoI'm thinking - they don't really expect you to call internationally to hang in a loop for an hour or so but they have calculated that a certain number of people will call internationally and hang in that loop whether or not any single individual is highly unlikely to do so.
- jgust 8y agoI'm willing to bet that they haven't calculated _anything at all_ and they are scrambling to put out the fire.
- freehunter 8y agoRemember when Equifax set up a "have I been hacked" site and that site was then immediately hacked?
- eletious 8y agoNot entirely on topic, but Marriott seems to be dealing with some internal phone abuse issues as well - calls going directly to hotel rooms (bypassing the front desk) and asking for card details to fix broken incidentals records. I got a call like this yesterday and found out that it's enough of an issue that they've printed out signs in the lobby warning guests to not hand out information.
- SmellyGeekBoy 8y agoThat's interesting. I've had a couple of calls like this in the past and have always insisted on going to reception instead of giving details over the phone. Thankfully mine turned out to be genuine.
- crazygringo 8y agoIs it time for us to simply accept that it's inevitable that, at some point, everything will be hacked, and hacked often? Should we be focusing our efforts more on how to make "identity theft" (i.e. fraud) more difficult, even when someone knows all your data? Something more tied to your physical self, whether 2FA or something else?
- freehunter 8y agoEveryone who knows about security already accepts that everything either already is hacked or will be hacked eventually and no one can stop it. There's a famous quote and I'm not sure if it's originally from former FBI Director Robert Mueller [1] or former Cisco CEO John Chambers [2]: "There are two types of companies: those that have been hacked, and those who don't know they have been hacked." [1] https://archives.fbi.gov/archives/news/speeches/combating-threats-in-the-cyber-world-outsmarting-terrorists-hackers-and-spies https://archives.fbi.gov/archives/news/speeches/combating-th... [2] https://www.networkworld.com/article/2952184/cisco-subnet/john-chambers-10-most-memorable-quotes-as-cisco-ceo.html https://www.networkworld.com/article/2952184/cisco-subnet/jo...
- brootstrap 8y agomi gringo. i accepted this fact a few years ago hah. If your sh aint hacked already, you better believe our Googlie Amazonian Apple overlords are listening to every word we say, logging every keystroke in browser etc. Have our overlords hacked our own life to steal personal data? Kind of seems like it. Oh well we are just one drop in bucket of millions of hacked americans. I'll just keep going with the flow, loading up my retirement funds and hoping the world dont crash in the next 70 years so i can see my family grow, retire, and spend time with the wifer
- Latteland 8y ago70 years? Are you 10 years old?
- deleted 8y ago[deleted]
- rednerrus 8y agoI do not envy their ops team.
- cs702 8y agoAs a first rough approximation, this figure includes everyone on HN. It appears to include everyone who's ever stayed in a room at a Marriott, St. Regis, Ritz-Carlton, Bulgari, W Hotel, JW Marriott, The Luxury Collection, Le Meridien, Renaissance, Westin, Tribute Portfolio, Sheraton, Autograph Collection, Design Hotel, Marriott Executive Apartments, Delta Hotels & Resorts, AC Hotels, Element, Gaylord, SpringHill Suites, Courtyard, Residence Inn, Fairfield Inn & Suites, Moxy Hotels, Protea Hotels, TownePlace Suites, Aloft, Four Points by Sheraton, or Marriott Vacation Club property. For reference, there are under 130M households in the US and around 200M households in the entire EU.
- cr1895 8y agoFrom the article: "The hotel chain said the guest reservation database of its Starwood division had been compromised by an unauthorised party." "Starwood's hotel brands include W Hotels, Sheraton, Le Méridien and Four Points by Sheraton. Marriott-branded hotels use a separate reservation system on a different network." edit: the Marriott website itself confirms as much that this is limited to Starwood properties. http://news.marriott.com/2018/11/marriott-announces-starwood-guest-reservation-database-security-incident/ http://news.marriott.com/2018/11/marriott-announces-starwood... " guest information relating to reservations at Starwood properties* on or before September 10, 2018.'" "* Starwood brands include: W Hotels, St. Regis, Sheraton Hotels & Resorts, Westin Hotels & Resorts, Element Hotels, Aloft Hotels, The Luxury Collection, Tribute Portfolio, Le Méridien Hotels & Resorts, Four Points by Sheraton and Design Hotels. Starwood branded timeshare properties are also included." Do you have other information?
- jayess 8y ago> * Starwood brands include: W Hotels, St. Regis, Sheraton Hotels & Resorts, Westin Hotels & Resorts, Element Hotels, Aloft Hotels, The Luxury Collection, Tribute Portfolio, Le Méridien Hotels & Resorts, Four Points by Sheraton and Design Hotels. Starwood branded timeshare properties are also included.
- isostatic 8y agoWhat possible reason would Marriot have to have details of my stay from 6 years ago on record, especially on their reservation system.
- donkeyd 8y agoI recently got added to Starwood Preferred Guest. I still don't know why they have my e-mail (don't seem to have stayed at any of their hotels), but I guess it's out there now, even though it wasn't in HIBP before.
- nkkollaw 8y agoThis is going to end so many marriages, it's not even funny.
- 0xmohit 8y agoThe New York Attorney General is opening an investigation into a Marriott data breach that may have affected 500 million guests. https://twitter.com/NewYorkStateAG/status/1068510072396029952 https://twitter.com/NewYorkStateAG/status/106851007239602995...
- swarnie_ 8y agoI would expect the EU to follow with GDPR shortly, massive fines incoming.
- shawn-butler 8y agoGreat massive fines, significant lawyer billing, some worthless credit monitoring service free for 6 months and screw the affected consumers. Let's see Target is probably the most obvious parallel: $202 million in reported legal fees and other costs. $18 million to states (fines). $39 million to the financial institutions affected by the breach and a whopping $10 million for the consolidated class action lawsuit (along with the $6.75 million for plaintiffs’ attorneys fees and expenses). Oh wait, Target annual profits are $20 billion? Never mind.
- lawnchair_larry 8y agoThey still don’t even use https, so this is not surprising.
- SketchySeaBeast 8y agoOutside of the privacy problems (which, let's be honest, our data is already out on the web) if you changed your credit card since your last visit you're probably safe on that particular financial attack vector, right?
- codedokode 8y agoIf they didn't keep the data from long ago, then the damage would be much smaller. Such companies definitely need some help from lawmakers. Companies shouldn't keep personal information for years.
- duxup 8y ago>It said an internal investigation found an attacker had been able to access the Starwood network since 2014. Jebus that seems like a long time before discovering it.
- ransford 8y agoMarriott's incident page [1] links to a Q&A page [2]. Apparently the forthcoming sorry-we-lost-your-data notifications will come from "starwoodhotels@email-marriott.com". "Let's immediately set up a separate domain name that looks like ours" remains one of the weirdest antipatterns in incident response. [1] http://news.marriott.com/2018/11/marriott-announces-starwood-guest-reservation-database-security-incident/ http://news.marriott.com/2018/11/marriott-announces-starwood... [2] https://info.starwoodhotels.com/ https://info.starwoodhotels.com/
- cm11 8y agoIs this to purposefully increase likelihood of getting caught in a spam/phishing filter? So they claim they've reached out while also (probably correctly) claiming it's not their fault if customers didn't get it.
- CobrastanJorji 8y agoInteresting theory. My theory was that there's incident management contractors get this sort of business and don't want to bother integrating with any existing company's infrastructure, so they just set up something entirely different.
- reaperducer 8y agoProbably not so much "don't want to bother" as "can't do it in a timely manner because of the company's internal processes" Once of the companies I work for has all kinds of crazy domains because the IT department and the Communications Department don't get along the way they should.
- ransom1538 8y agoClose to my theory! Basically, they need to send out millions of email fast. This email, with a bunch of legal text will probably have a high 'mark as spam' rate. This will destroy the domain's marketing ability. SO! The marketing guy won the argument in the meeting: don't use the root domain.
- hamilton 8y agoA handful of years ago, Paul Ohm wrote about a concept he called the "Database of Ruin" [0]. I think about it every time one of these pieces of news breaks. "Once we have created this database, it is unlikely we will ever be able to tear it apart." [0] https://hbr.org/2012/08/dont-build-a-database-of-ruin https://hbr.org/2012/08/dont-build-a-database-of-ruin
- imnotlost 8y agoI'm almost certainly in the database. So I have to get a new passport, get a new phone number, get a new credit card, change my email address... in the US, can I sue in small claims court to recover the costs of doing these things?
- randomsofr 8y agodon't forget to change gender and date of birth as well
- bduerst 8y agoI just signed in to Marriott.com see what info they have on me that was stolen, and was forced to change my password. It even required email verification, which is good. Then when I tried to log in with my new password I was rejected, saying my account is 'under audit' for suspicious activity. God dammit. Is anyone else unable to log in?
- drcode 8y agoA breach like this should mean that Marriott should immediately be in bankruptcy, since the potential damage to any individual customer is well above multiple thousands of dollars. I wish some of these giant companies would see some real consequences for their lax security practices.
- drcode 8y agoIs anyone else noticing unusual downvotes on this thread? Anyone think it's plausible a Marriot damage control team is participating on this thread?
- pc86 8y agoI think it's unlikely that a Marriott "damage control team" cares about comment vote totals on an HN thread.
- drcode 8y agoI would usually agree, but near as I can tell the vast majority of the top-level comments in this thread have a negative score and I find that surprising.
- ryacko 8y agoThe most famous damage control team: https://en.m.wikipedia.org/wiki/Jackie_(dog) https://en.m.wikipedia.org/wiki/Jackie_(dog) Never underestimate collective stupidity.
- Jabbles 8y agoHow could it affect 500 million? 1 in 16 people worldwide have stayed in a Marriott hotel? That seems like a lot...
- pc86 8y ago500 million reservations from 150 million people/companies/entities.
- cmurf 8y agoHistory being a guide, Marriott will obtain a contract with some financial security monitoring service, and offer a ~12 month free period for affected consumers. I've always thought these products are b.s. The advertising is scammy. I'm betting they leak even more data, like your purchase histories. Does anyone know of the efficacy of these monitoring services? If they were really even slightly more effective than even odds, I would say that consumer protection laws should require free monitoring for a longer period, say 24 months or even 36 months. Ironically though, proper monitoring means sharing all of this same personal information with a 3rd party, and then some. I also wonder if it's just more effective to take advantage of the free credit report freezing feature, since that doesn't require me to share even more personal information with a 3rd party; and actually restricts access to personal information instead of expanding it.
- magnamerc 8y agoWhen you start using Ethereum and web 3.0, the solution to data security becomes quite clear. I'm sure I'm gonna get roasted here for even mentioning this, but you'll all eventually come around.
- brewdad 8y agoThis was the kick in the pants I needed to finally take the time to freeze my credit. I don't know how much it will help but it can't hurt, I guess.
- calebm 8y agoA nice article to read while sitting here in a Marriott.