Marriott fined £0.05 for each of the 339 million hotel guests whose data crooks were stealing for four years
- Reference: 1604066889
- News link: https://www.theregister.co.uk/2020/10/30/marriott_starwood_hack_fine_just_18_4bn/
- Source link:
The fine was imposed as a regulatory punishment for [1]the 2018 Starwood Hotels megabreach despite Marriott not accepting liability for wrongdoing.
Although the attack was originally thought to have exposed half a billion records in the chain's guest reservation database, later investigations revised that figure downwards.
Within the exposed data were 5.25 million guests' passport numbers, stored without encryption, as well as 18.5 million encrypted passport numbers and 9.1 million encrypted credit card numbers.
Adding insult to public injury, the ICO cut Marriott's fine by four-fifths from its [2]originally signalled value of £99m – and then [3]dragged its heels [4]repeatedly .
"When a business fails to look after customers' data, the impact is not just a possible fine, what matters most is the public whose data they had a duty to protect," said Information Commissioner Elizabeth Denham in a canned statement.
A Marriott spokeswoman told The Register : "Marriott deeply regrets the incident," adding that the US hotel chain "remains committed to the privacy and security of its guests' information and continues to make significant investments in security measures for its systems."
Watertight like a colander
According to the ICO's detailed monetary penalty notice
[5]PDF
, the hack was years in the making and was only detected when the attackers started sniffing around payment card data, having gone unnoticed for four years inside Starwood Hotels' systems.Starwood was bought by Marriott in 2016, though the acquired chain's systems remained separate from Marriott's own IT estate until the former were shut down post-buyout.
Unidentified malicious people managed to sneak a web shell onto a machine inside Starwood Hotels' networks in July 2014. That shell was then used to plant various remote-access trojans (RATs) onto Starwood's system and password-slurping open-source tool Mimikatz, which the attackers used to compromise more network accounts.
Those accounts included ones without multi-factor authentication – and accounts with admin creds for key databases. Still the attackers' actions went unnoticed.
Between April 2015 and May 2016, the attackers quietly created database dumps "with a view to exfiltrating all the data contained" at once, as the ICO summarised it. They finally tripped an alarm in September 2018, four years after first entry, after running a count on a table named "Guest_Master_profile" containing card data, which flagged up on the IBM Guardium product that was deployed to highlight up any suspicious database operations.
Accenture, which was monitoring Guardium, told Marriott what it had seen. The resulting probe revealed that Accenture staffers' own credentials had been compromised in July 2018 and were being used by the attackers.
By October 2018, Marriott had also realised that a separate group of attackers had managed to deploy in-memory malware across payment terminals at eight hotels the ICO declined to identify beyond saying they were not located in the European Economic Area, therefore falling outside its regulatory remit.
Poor infosec practices partly triggered GDPR liability
Despite being forced to admit that Starwood (and PCI-DSS auditors) had given misleading assurances about the extent of MFA deployment across accounts with access to the card data environment, Marriott was able to escape sanction for that. However, its corporate failure to spot the personal data dumping after the attackers got in counted against it.
"In this case, appropriate monitoring would have included the appropriate logging of user activity, especially in relation to privileged users," said the ICO. "Marriott's failure to log user activity in this way was inconsistent with its obligations under the GDPR."
The regulator continued: "It would have been appropriate for Marriott to have implemented a defence in-depth strategy." The ICO went on to demolish Marriott's protestations that whitelisting known good accounts wouldn't itself have been enough to stop the attackers.
Intriguingly, a redacted section of the report refers to a "script" developed by Starwood and seemingly used by the attackers. That script "allowed for AES-128 encrypted entries in a database table to be decrypted."
Pages 28-40 of the ICO [6]monetary penalty notice [PDF] warrant close reading by conscientious techies and managers alike wanting to know how IT security practices played a direct role in deciding how badly Marriott had broken the EU's GDPR. Though Britain leaves the EU-controlled GDPR regime in January, it is mirrored in the Data Protection Act 2018 and will remain in effective force.
The ICO said it would have imposed a £28m penalty but for Marriott having established a data breach website and call centre to serve a data breach hotline. It also emailed customers to notify them, and cooperated with ICO investigators. That won it a 20 per cent discount to £22.4m, with the COVID-19 pandemic scoring it a further £4m discount.
Francis Gaffney, director of threat intelligence at email security biz Mimecast, opined: "Too often, regulation is viewed as a burden, but organisations should start to view it through the lens of their customers, partners, or employees. If a customer trusts you with their data, you owe it to them to protect it and ensure it is safe. Many organisations are having to pay financial penalties for such data breaches and it is only afterwards that the cost of a breach now outweighs the potential savings from not investing in security and data management solutions." ®
Get our [7]Tech Resources
[1] https://www.theregister.com/2018/11/30/marriott_starwood_hotels_500m_customer_records_hacked/
[2] https://www.theregister.com/2019/07/09/marriott_hotels_ico_fine_intention_99m_starwood_breach/
[3] https://www.theregister.com/2020/01/13/ico_british_airways_marriott_fines_delayed/
[4] https://www.theregister.com/2020/04/06/ico_data_protection_fines_ba_marriott_hack_postponed/
[5] https://ico.org.uk/media/action-weve-taken/mpns/2618524/marriott-international-inc-mpn-20201030.pdf
[6] https://ico.org.uk/media/action-weve-taken/mpns/2618524/marriott-international-inc-mpn-20201030.pdf
[7] https://whitepapers.theregister.com/
Re: Bafflingly Shameful
And garnish all executive bonuses (including signing bonuses) until the sum is paid in full.
To stop it happening again ...
which should be one of the ICO's aims, should they not have insisted that Marriott be audited by an independent White Hat type organisation for 10 years ? Hopefully the WH types would kick up a fuss at poor/sloppy practice and make them fix it.
I do not know if the ICO has the power to order this, if not then time to get a quick bill through parliament.
Re: To stop it happening again ...
As long ago as 2009 I suggested to the then deputy information commissioner that fines should be replaced by enforced specific remediation and fulfilment audit at the expense of the subject of the action. His response was that they couldn't contemplate affording that as their revenues were insufficient.
The ICO's funds still are insufficient, primarily because it's in a bind. It can't be funded by government as there would be a conflict of interest if it had to action a government data breach; it can't be funded by fines as there might be suspicion of malpractice in aid of revenue. The existing model is a registrant fee based on scale of organisation, and it clearly yields insufficient funding. Our annual fee is a mere £40 and that's probably the fee the majority of companies pay. I'd be quite content to see it doubled or trebled, which would make a big difference to the ability of the ICO to take on duties that actually prevent data breaches, quite apart from supporting its other workload. The last time I enquired the ICO was so overloaded that it took several months just for a complaint to be allocated a case officer.
I strongly suspect that for the same reasons the downward negotiation of fines is a trade off between the cost of litigation and the effect of the penalties. A typical business will spend many time more on a legal challenge than they save as a result of its success, as what matters is "reputation". The ICO can't afford to do that, but has to cut its losses much sooner as appeal litigation runs to millions.
Re: To stop it happening again ...
Agreed, but not any company that has audited them since 2004...
An upside to COVID
"with the COVID-19 pandemic scoring it a further £4m discount".
At last their shareholders get an upside from COVID. Shameful.
COVID discount?
So China unleashed hell on the world, and because of that some rich hotel chain gets a £4M discount on its punishment?
Can someone please explain what the connection is between these two things?
Re: So China unleashed hell on the world
Because if it'd manifested anywhere else it wouldn't have been spread around the world by humans?
I think your bigotry is showing......
Re: Can someone please explain what the connection is between these two things?
It's more socialism for the Rich. When they get a fine, if they're having a hard time paying it, it's reduced.
Try that next time you get nicked for speeding whilst poor.
Re: COVID discount?
FYI there seems to be little or no evidence that C19 came from China. Retrospective tests have shown that at least one person died in France of C19 weeks before it was 'discovered' in China.
A lot of this comes down to the ICO not having a big enough legal budget. Basically it can't afford to take on these big multinationals so it gives in when they says "how much to make this go away". Remember the ICO doesn't get to keep these fines they go to the Treasury.
Really the ICO should be able to hang onto some of this money to add to its legal fund to makes sure it is not in the same position next time of being unable to defend its own decisions.
If the fine is 0.05/record, wouldn't it make financial sense to just sell all the records that you have on the black market? I'm pretty sure you can get a lot more than that for passport details, no?
Bafflingly Shameful
As bafflingly shameful as BA’s ‘get away near Scott-free’ knuckle rap.
The ICO Chair should Fucking resign in shame.
Simple solution - as with BA - take the £18m as a down payment on an instalment plan tied to the companies recovery. No boardroom bonuses until paid off.
Simple, fair, proportionate and helps out with short-term cash flow/revenue issues. 5-10 year payment plan please.
BA and Marriott must be pissing themselves in glee at this. It’s disgusting - esp.. In light of BA’s casual disregard of the law on refunds and employment practices too.
Habitual offenders have been rewarded with the equivalent of a misdemeanour punishment.