Marriott Hacking Exposes Data of Up to 500 Million Guests

By Amie Tsang

Image
Marriott International acknowledged on Friday that an “unauthorized party had copied and encrypted information” about 500 million customers on one of its reservations systems in September.CreditCreditMauritz Antin/EPA, via Shutterstock

LONDON — The Marriott International hotel chain said on Friday that the database of its Starwood reservation system had been hacked and that the personal details of up to 500 million guests going as far back as 2014 has been compromised.

The hotel group, which runs more than 6,700 properties around the world, was informed in September about an attempt to access the database, and an investigation this month revealed that unauthorized access had been made on or before Sept. 10, Marriott said in a statement.

The investigation also found that an “unauthorized party had copied and encrypted information, and took steps toward removing it,” the statement said.

The hotel chain said that personal details including names, addresses, dates of birth, passport numbers, email addresses and phone numbers for hundreds of millions of guests may have been compromised.

Hackers also obtained encrypted credit-card information for some customers, but it was unclear if the hackers would be able to use those payment details.

“We deeply regret this incident,” Arne Sorenson, Marriott’s president and chief executive officer, said in a statement. “We fell short of what our guests deserve and what we expect of ourselves. We are doing everything we can to support our guests, and using lessons learned to be better moving forward.”

The company said it had set up a dedicated website and call center to deal with questions guests might have about their personal information, and had notified regulatory and legal authorities. Marriott also said it would try to reach affected customers on Friday to inform them of the security breach.

Marriott, based in Bethesda, Md., is the world’s largest hotel chain, having bought Starwood Hotels and Resorts Worldwide two years ago for $13.6 billion. The merger brought brands like Westin, W and Sheraton under the same roof, and prompted questions about whether the brands being acquired would lose some of their cool factor.

Customers also complained about problems with rewards programs after efforts to merge data from Starwood’s rewards program into Marriott’s left the records of millions of customers in limbo for weeks.

The company has also been grappling in recent weeks with strikes by thousands of workers, who walked out of 49 hotels in nine cities to call for better health care, wages and protection from sexual harassment.

Follow Amie Tsang on Twitter: @amietsang.