Marriott fined £18.4m for security breach - TravelMole


Marriott fined £18.4m for security breach

Wednesday, 30 Oct, 2020 0

The Information Commissioner’s Office (ICO) has fined Marriott International Inc £18.4 million for failing to keep millions of customers’ personal data secure.

The fine is far less than the £99 million the ICO warned Marriott may have to pay.

Marriott estimates that 339 million guest records worldwide were affected following a cyber-attack in 2014 on Starwood Hotels and Resorts Worldwide Inc.

The attack, from an unknown source, remained undetected until September 2018, by which time the company had been acquired by Marriott.

The personal data involved differed between individuals but may have included names, email addresses, phone numbers, unencrypted passport numbers, arrival/departure information, guests’ VIP status and loyalty programme membership number.

The precise number of people affected is unclear as there may have been multiple records for an individual guest. Seven million guest records related to people in the UK.  

The ICO’s investigation found that there were failures by Marriott to put appropriate technical or organisational measures in place to protect the personal data being processed on its systems, as required by the General Data Protection Regulation (GDPR).

Information Commissioner, Elizabeth Denham, said: "Millions of people’s data was affected by Marriott’s failure; thousands contacted a helpline and others may have had to take action to protect their personal data because the company they trusted it with had not.

"When a business fails to look after customers’ data, the impact is not just a possible fine, what matters most is the public whose data they had a duty to protect."

The ICO’s investigation traced the cyber-attack back to 2014, but the penalty only relates to the breach from 25 March 2018, when new rules under the GDPR came into effect.

Because the breach happened before the UK left the EU, the ICO investigated on behalf of all EU authorities as lead supervisory authority under the GDPR. The penalty and action have been approved by the other EU DPAs through the GDPR’s cooperation process.

How it happened

In 2014, an unknown attacker installed a piece of code known as a `web shell’ onto a device in the Starwood system giving them the ability to access and edit the contents of this device remotely.

This access was exploited in order to install malware, enabling the attacker to have remote access to the system as a privileged user. As a result, the attacker would have had unrestricted access to the relevant device, and other devices on the network to which that account would have had access.

Further tools were installed by the attacker to gather login credentials for additional users within the Starwood network. With these credentials, the database storing reservation data for Starwood customers was accessed and exported by the attacker.

Which? welcomed the ICO’s action, but warned: "Our research earlier this year suggested that Marriott had not learned lessons from previous data breaches and still had serious vulnerabilities on its websites that could leave customers exposed to opportunistic cybercriminals."

Kate Bevan, Editor of Which? Computing, said: "Some people will be frustrated if they’ve suffered financially and emotionally from this data breach but had no redress.

"The government should provide a much clearer route to this by allowing for an opt-out collective redress regime that deals with mass data breaches."

See also: Marriott International in another data breach



 

profileimage

Lisa

Lisa joined Travel Weekly nearly 25 years ago as technology reporter and then sailed around the world for a couple of years as cruise correspondent, before becoming deputy editor. Now freelance, Lisa writes for various print and web publications, edits Corporate Traveller’s client magazine, Gateway, and works on the acclaimed Remembering Wildlife series of photography books, which raise awareness of nature’s most at-risk species and helps to fund their protection.



Most Read

Tony from Gatto’s Pizza on Columbus’s Unique Pizza Trail

Sophia Hyder Hock on Global Social Inclusion in Tourism

Sustainable Tourism: Don Welsh on Community Values and Global Collaboration

Jane Cunningham: Enhancing European Engagement in Tourism

Kristin Dunne: Navigating Destination Strategy

Revolutionizing Mobile Connectivity: Boris Bijlstra on HUBBY eSIM

Capturing Glasgow’s Vibrancy: An Interview with Susan Deighan, Chief Executive of Glasgow Life

Lebua Hotel & Resorts: Rajan Khurana on Hospitality and Bangkok’s Charms

Sustainable Tourism and Growth: Insights from Chiravadee Khunsub from Tourism Authority of Thailand

Revolutionizing Travel: SmartSIM USA’s Dale Takio Unveils the Power of E Sims

TravelMole Interview with Hishan Singhawansa, Deputy CEO of Cinnamon Hotels & Resorts, Sri Lanka

Unveiling the Essence of Magari Tours: A Dive into Authentic Italian Experiences
TRAINING & COMPETITION

Our emails to you has bounced travelmole.com Or You can change your email from your profile Setting Section

Your region selection will be saved in your cookie for future visits. Please enable your cookie for TravelMole.com so this dialog box will not come up again.

Price Based Country test mode enabled for testing United States (US). You should do tests on private browsing mode. Browse in private with Firefox, Chrome and Safari