Monday, April 21, 2025
HomeCyber AttackHackers Stolen 500 Million Guests Personal Information From Starwood Hotels Guest Reservation...

Hackers Stolen 500 Million Guests Personal Information From Starwood Hotels Guest Reservation Database

Published on

SIEM as a Service

Follow Us on Google News

Marriott International announced a security breach that affected more than 500 million guests who made a reservation at Starwood Hotels and resorts. Marriott International acquired Starwood Hotels & Resorts in the mid-2016.

Mariott identified about the intrusion on September 10, after receiving an alert form their internal security testing tool. They learned an unauthorized access to the Starwood guest reservation database in the United States.

The hotel chain then worked with security experts to determine the root cause and how long the hackers having access to the database, reads their breach notice.

- Advertisement - Google News

According to the investigation, Marriott learned hackers gained unauthorized access to the Starwood network since 2014, they copied, encrypted information and taken steps to remove it.

On November 19, 2018, Marriott managed to decrypt the information and determined that the contents were from the Starwood guest reservation database and they working to identifying the duplicate information in the database.

Possibly the attackers exfiltrated approximately 500 million guests who made a reservation at a Starwood property. Among the exfiltrated 500 million guests data, 327 million of the guest records including the following information.

The details include name, mailing address, phone number, email address, passport number, Starwood Preferred Guest (“SPG”) account information, date of birth, gender, arrival and departure information, reservation date, and communication preferences.

Some of the guest payment card information also exposed, but they are encrypted with Advanced Encryption Standard encryption (AES-128).

“We deeply regret this incident happened,” said Arne Sorenson, Marriott’s President, and Chief Executive Officer. “We fell short of what our guests deserve and what we expect of ourselves. We are doing everything we can to support our guests, and using lessons learned to be better moving forward.”

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Dixons Carphone Suffers Massive Data Breach, 5.9 Million Payment Cards & 1.2 Million Personal Data Exposed

37,000 Eir Customer’s Personal Data Exposed as their Company Laptop Stolen

Dell Hacked – Data Breach Exposed Names, Email addresses & Hashed Passwords

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Infostealer Attacks Surge 84% Weekly Through Phishing Emails

The volume of infostealer malware distributed through phishing emails has surged by 84% week-on-week...

North Korean IT Workers Use Real-Time Deepfakes to Infiltrate Organizations Through Remote Jobs

A division of Palo Alto Networks, have revealed a sophisticated scheme by North Korean...

New Phishing Technique Hides Weaponized HTML Files Within SVG Images

Cybersecurity experts have observed an alarming increase in the use of SVG (Scalable Vector...

Detecting And Blocking DNS Tunneling Techniques Using Network Analytics

DNS tunneling is a covert technique that cybercriminals use to bypass traditional network security...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Infostealer Attacks Surge 84% Weekly Through Phishing Emails

The volume of infostealer malware distributed through phishing emails has surged by 84% week-on-week...

North Korean IT Workers Use Real-Time Deepfakes to Infiltrate Organizations Through Remote Jobs

A division of Palo Alto Networks, have revealed a sophisticated scheme by North Korean...

New Phishing Technique Hides Weaponized HTML Files Within SVG Images

Cybersecurity experts have observed an alarming increase in the use of SVG (Scalable Vector...