Marriott data breach of reservation system affects 500 million guests

By News Staff and The Canadian Press

Marriott’s reservation system has been breached, affecting 500 million guests, including Canadians.

The database included guest information relating to reservations at the hotel’s Starwood network made on or before Sept. 10. 2018.

Any Canadian who stayed at any legacy Starwood-branded hotels in Canada may have been affected, Marriott said.

Hotels that were branded under Starwood are W Hotels, St. Regis, Sheraton Hotels & Resorts, Westin Hotels & Resorts, Element Hotels, Aloft Hotels, The Luxury Collection, Tribute Portfolio, Le Meridien Hotels & Resorts, Four Points by Sheraton and Design Hotels. Starwood branded timeshare properties are also included.

There are nine hotels in Toronto that were formally branded as Starwood: Sheraton Centre Toronto Hotel, St. Regis Toronto (formerly the Adelaide Hotel), Westin Harbour Castle, The Westin Prince,
Four Points By Sheraton Toronto Airport East, Sheraton Toronto Airport Hotel and Conference Centre, Westin Toronto Airport, Four Points by Sheraton Toronto Airport and Sheraton Gateway Hotel.

Marriott does not have the number of Canadian guests who may have been affected.

Canadians who travelled globally and stayed at a Starwood-branded hotel may have also been affected.

Unauthorized access to the database has been happening since 2014, the hotel announced on Friday.

For as many as two-thirds of those affected, exposed data could include mailing address, phone number, email address, passport number, Starwood Preferred Guest account information, date of birth, gender, arrival and departure information, reservation date and communication preferences. For some guests, the information was limited to name and sometimes other data such as mailing address, email address or other information.

“We fell short of what our guests deserve and what we expect of ourselves,” CE0 Arne Sorenson said in a prepared statement. “We are doing everything we can to support our guests, and using lessons learned to be better moving forward.”

Marriott said email notifications to those who may have been affected will begin rolling out Friday.

Corey Larocque, a spokesperson with the Canadian Office of the Privacy Commissioner, said Marriott informed the office of the breach today and the office is “following up” with the company.

Due to confidentiality, Larocque said he could not provide further details, but said the commissioner has not opended a formal investigation or received complaints around the breach.

Marriott acquired Starwood Hotels in 2016. When their merger was announced in November 2015, Marriott had 54 million members of its loyalty program and Starwood had 21 million. Many travellers were members in both programs.

When the merger was first announced in 2015, Starwood had 21 million people in its loyalty program.

How can you tell if you’ve been affected, and what can you do if you are? Here are some things to know:

THE SCOPE

The breach affects only the hotel brands operated by Starwood before Marriott bought it in 2016. The brands include W Hotels, St. Regis, Sheraton, Westin, Element, Aloft, The Luxury Collection, Le Meridien and Four Points. Starwood-branded timeshare properties are also affected. Marriott-branded chains aren’t affected, as data on those stays are on a different network.

Marriott says the breach affected reservations at Starwood properties through Sept. 10, 2018. That could include reservations made for a future stay.

AM I AFFECTED?

Marriott says it began sending emails to affected guests on Friday. Be careful, though, when you receive an email about this breach, as hackers may be using the incident to dupe you into providing passwords or installing malicious software. If you get such an email, it’s best to go directly to a website Marriott has set up on this breach. There, you can find phone numbers to call.

WHAT SHOULD I DO?

Marriott is offering free one-year subscription to a monitoring service, WebWatcher. This service monitors websites where stolen information is shared. If your details are found, you’ll get an alert. It’s available only for guests from the U.S., Canada and the U.K. U.S. residents are also eligible for consultation with a fraud specialist and reimbursement for legal and other expenses related to identity theft.

Though Marriott doesn’t know yet whether hackers got all the keys to unlock encrypted credit card data, the company says it’s quite possible they did. You should review your credit card statements for unauthorized activities.

MY INFORMATION HAS ALREADY BEEN HACKED. WHY SHOULD I WORRY NOW?

Hacks involving retailers and other businesses are usually limited to names, email and physical addresses and passwords. In some cases, payment cards are also stolen, meaning you need to replace your card and update all the services with auto payment enabled.

For about two-thirds of the 500 million Starwood guests affected, hackers may also have the date of birth and gender, which can contribute to identity theft.

Hackers also got passport numbers on this group of guests if the hotel had them. The good news is that criminals often need the actual passport to do anything with your number.

The database may have details on future stays, including arrival and departure dates, along with your home address. Burglars could figure out when you’ll be away. Ask a friend or neighbour to check your home, or arrange a house sitter.

WHAT SHOULD I DO IN THE FUTURE?

There’s not much you can do to prevent such hacks, but you can mitigate the damage.

For starters, consider using a credit card rather than a debit card, as credit cards typically offer more protections against losses.

Even if you weren’t affected in this breach, request the free credit reports anyhow. After all, they are free. Details are at the Marriott website. Check the website haveibeenpwned.com to see if your information has been stolen in other breaches.

And think twice when businesses ask you for personal information. Does the hotel really need your date of birth? Perhaps the information is requested for loyalty programs that might give you free stays – but nothing’s really free, and your data has value to both the hotel and potential hackers.

Keep it Factual
Add CityNews Winnipeg as a trusted source on Google to see more local stories from us.

Top Stories

Top Stories

Most Watched Today