Friday, October 11, 2024
HomeCyber Security NewsMarriott Hacked - Over 20 GB of Data Including Credit Card Leaked

Marriott Hacked – Over 20 GB of Data Including Credit Card Leaked

Published on

Malware protection

Marriott Hotels & Resorts International based in Bethesda, Maryland suffered a data breach. An unnamed hacking group claimed to have stolen approximately 20GB of data including personal and credit card details of guests.

According to a Marriott spokesperson, “the company is aware of a threat actor who used social engineering to trick one associate at a single Marriott hotel into providing access to the associate’s computer.”

 The access “only occurred for a short amount of time on one day. Marriott identified and was investigating the incident before the threat actor contacted the company in an extortion attempt, which Marriott did not pay”’ he added.

- Advertisement - SIEM as a Service

Exposing Information of Hotel Guests and Employees

The incident involves access to around 20 GB of files, which included credit card information and confidential information about guests and workers from an employee at the BWI Airport Marriott in Baltimore.

The reports say the attackers “emailed numerous employees” at Marriott about the breach, and had been in at least limited communications with Marriott.

The attack vector involved the hackers tricking a Marriott associate into giving access to the associate’s computer through ‘social engineering.

The attackers provided Data breaches, samples of the documents they claimed to have stolen, and screenshots posted to the site state to verify reservation logs for airline crew members from January 2022 and credit card authorization forms.

According to data breaches, which first reported the attack, the hackers have documents detailing names and other details of guests, as well as credit card information used to make bookings.

The company confirmed the breach to data breaches, but said the information stolen was mostly “non-sensitive business files”. Also, they have informed between 300-400 affected parties, as well as relevant data protection watchdogs and law enforcement agencies.

Marriott’s Data Breaches in the Past

Earlier, in November 2018, Marriott suffered serious data breaches in the past. The hack involved the theft of data relating to some 500 million customers and was later linked to Chinese state-sponsored hackers, a claim the Chinese government denied.

Marriott suffered yet another data breach believed to have involved data that includes the PII of some 5.2 million guests and is believed to have been accessed by an unknown third party using the login credentials of two employees at a group hotel operated as a franchise.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Threat Actor ProKYC Selling Tools To Bypass Two-Factor Authentication

Threat actors are leveraging a newly discovered deepfake tool, ProKYC, to bypass two-factor authentication...

Mozilla Warns Of Firefox Zero-Day Actively Exploited In Cyber Attacks

A critical use-after-free vulnerability affecting Firefox and Firefox Extended Support Release (ESR) is being...

SpyCloud Embeds Identity Analytics in Cybercrime Investigations Solution to Accelerate Insider and Supply Chain Risk Analysis & Threat Actor Attribution

IDLink, SpyCloud’s new automated digital identity correlation capability, is now core to its industry-leading...

Abusix and Red Sift Form New Partnership, Leveraging Automation to Mitigate Cyber Attacks

The agreement has marked over 600,000 fraudulent domains for takedown in just two months...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Threat Actor ProKYC Selling Tools To Bypass Two-Factor Authentication

Threat actors are leveraging a newly discovered deepfake tool, ProKYC, to bypass two-factor authentication...

Hackers Exploiting Zero-day Flaw in Qualcomm Chips to Attack Android Users

Hackers exploit a zero-day vulnerability found in Qualcomm chipsets, potentially affecting millions worldwide.The flaw,...

Foxit PDF Reader Vulnerability Let Attackers Execute Arbitary Code

Researchers recently disclosed six new security vulnerabilities across various software, as one critical vulnerability...