News: 1657116013

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Marriott Hotels admits to third data breach in 4 years

(2022/07/06)


Marriott Hotels has leaked data to attackers again and this time the culprits made off with 20GB of information, which reportedly included credit card info and internal company documents.

The unnamed group behind the attack contacted privacy news site DataBreaches to [1]share the news that it broke into a server at the Marriott hotel at Boston/Washington International Airport in Maryland late last month.

The group shared screenshots of customer credit card authorization forms including full card details and said its members were in communication with Marriott, but the hotel chain stopped talking.

[2]

"We were acting like a red hat organization and they just stopped communicating with us," a spokesperson told DataBreaches.

[3]

[4]

So-called "red hat hackers" are the less ethical cousins of white hats, the latter of whom often operate with permission from the organizations they target.

Both Marriott and the miscreants said that no money was exchanged, but the group did admit cash may have been the reason why communications dried up.

[5]

"[Marriott] went silent for no reason, it might be because of the high pricing, but we are always willing to find a deal with our clients and told Marriott that we can provide all the discounts in the world," the culprits told DataBreaches.

The attackers claim they are an international group that [6]doesn't encrypt data because they don't want to interfere with businesses, and they say they don't attack governments or critical infrastructure.

How'd they get in? Social engineering

According to statements that Marriott made to DataBreaches, the attackers used social engineering to access a single employee's computer. Marriott said they have no evidence the criminals accessed files beyond what the person they tricked had access to, and said they contained the breach within six hours.

Based on documents seen on DataBreaches, some of which were shared in the above-linked post, some of the information stolen was definitely sensitive. Internal business documents were included, while others contained information on hotel guests and staff including corporate card numbers, wage data, personal identifiable information and even a personnel assessment of a staff member at the hotel.

[7]Dutch watchdog fines Booking.com €475k after it kept customer data thefts quiet for more than 3 weeks

[8]Marriott fined £0.05 for each of the 339 million hotel guests whose data crooks were stealing for four years

[9]Marriott Hotels hacked AGAIN: Two compromised employee logins abused to siphon off 5.2m guests' personal info

[10]Marriott's got 99 million problems and the ICO's one: Starwood hack mega-fine looms over

Marriott said it has to notify between 300 and 400 people, both guests and employees, due to the breach.

This data breach is only the latest attack on a Marriott-owned hotel. Most recently, attackers made off with [11]5.2 million guest records in 2020. A [12]2018 data leak was even larger , with 383 million booking records, 5.3 million unencrypted passport numbers and tens of millions of encrypted records stolen, too. In the case of the 2018 leak, it was breach of Marriott's Starwood subsidiary's guest reservation network – which it bought in 2016. That leak exposed the entire database – a full 500 million guest bookings over four years, making it one of the biggest breaches of an individual organization ever.

What has Marriott learned from all those breaches? According to the people behind the latest attack, not much. "Their security is very poor, there were no problems taking their data. At least we didn't get access to the whole database, but even the part that we took was full of the critical data," the group said.

[13]

The Register has contacted Marriott to learn more, but have yet to receive a reply. ®

Get our [14]Tech Resources



[1] https://www.databreaches.net/exclusive-marriott-hacked-again-yes-heres-what-we-know/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YsWxnSGWBNl9q0x63jbnIAAAAMk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YsWxnSGWBNl9q0x63jbnIAAAAMk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YsWxnSGWBNl9q0x63jbnIAAAAMk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YsWxnSGWBNl9q0x63jbnIAAAAMk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2022/06/25/ransomware_gangs_extortion_feature/

[7] https://www.theregister.com/2021/04/01/booking_dot_com_fine/

[8] https://www.theregister.com/2020/10/30/marriott_starwood_hack_fine_just_18_4bn/

[9] https://www.theregister.com/2020/03/31/marriott_hotels_hacked_5m_guests/

[10] https://www.theregister.com/2019/07/09/marriott_hotels_ico_fine_intention_99m_starwood_breach/

[11] https://www.theregister.com/2020/03/31/marriott_hotels_hacked_5m_guests/

[12] https://www.theregister.com/2019/01/04/marriott_stolen_passport_numbers/

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YsWxnSGWBNl9q0x63jbnIAAAAMk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[14] https://whitepapers.theregister.com/



Three strikes

Wellyboot

Oops sorry doesn't cut it here.

New directors please..

Motivation

wub

Ooops. Marriott can't seem to keep people from stealing their customer's data from their systems.

The only consequences for a data breach like this are a couple of public "apologies", perhaps a small fine, maybe even a ransom if that's the way it went. Big deal, their financial loss is probably less than insurers would charge them. Particularly insurers who have been careful to estimate the actual risk by reviewing processes and practices.

What organizations like this need is some form of serious financial motivation to make it worth their while to protect other people's data that they keep. But that likely means regulation. At least in the US, that can't be done - too many lobbyists, too little actual governing.

Business opportunity

Eclectic Man

I just phoned up one of my pension companies. They had an incorrect phone number for me and an incorrect email address. Not a mistake, as you might at first think, but actually someone has been trying to steal my pension funds, and has set up false accounts with a couple of banks, free email service provider etc. A few years ago they got away with nearly £100k from my accounts, all from the comfort of their extinct volcano HQ offices but not by subverting me, just the companies I had saved with (I got my money back eventually).

As the UK's 'ActionFraud', takes no actual action whatsoever for personal callers, if you have no conscience, but some social engineering and IT skills and like to work from home, this is a business opportunity that pays big, with likely little risk of actually being caught. Please do not do this, logging on to your pension provider web site to discover your account balance is £0 is a very shocking experience.

sitta_europea

There must come a time when one has to say that the evidence is overwhelming that either the top management is completely inept, or it doesn't give a flying duck.

In this case, I think, even if it hadn't already happened a while ago, surely it has now.

I'm very glad that they've never scanned any of my credit cards, nor any of my ID documents, and if it's left up to me, they never will.

It's just a great shame that if the chain suffers, or even goes bust, almost inevitably the ordinary hard-working people who are employed by the business (and have no way to contribute to its IT security, even if it were reasonable to expect it of them) will suffer far more than the senior management.

At what point could it be said that the negligence was criminal? It can't be far off.

Fred Daggy

“Once is happenstance. Twice is coincidence. Three times is enemy action” Ian Fleming

I'd argue that the enemy in this case is top management. A deliberate and considered lack of competant action. I smell a lawsuit that might take the company AND the directors down.

Beer icon, but really deserves Beer and Popcorn. I will enjoy watching the fallout from this - to serve as a warning to others.

"A deliberate and considered lack of competant action"

Mike 137

Never ascribe to malice what can be perfectly explained by incompetence. The fundamental problem (which I've encountered consistently for decades of consulting) is that security is about 'IT', but almost all the successful attacks these days (and for quite some time already) result from manipulating the psychology of folks who haven't been taught what the hazards are, how to recognise them, or how to counter them. 'Security awareness training' (even where it's undertaken) is an almost universal waste of time as it doesn't address the problems in terms the trainee can relate to. Add to the mix an effective failure of governance whereby responsibility is delegated without oversight (what I call 'fire and forget management') and the multiple breaches are fully explained, as nobody at any level of the organisation learns from any of them so they're surprises every time..

Eclectic Man

Fred Daggy> “Once is happenstance. Twice is coincidence. Three times is enemy action” Ian Fleming

I see your Ian Fleming and raise you a Lady Bracknell:

“To lose one parent, Mr. Worthing, may be regarded as a misfortune; to lose both looks like carelessness.”

(The Importance of Being Earnest by Oscar Wilde)

(Sorry, but I need a bit of cheering up at the moment.)

clients

Valeyard

we are always willing to find a deal with our clients and told Marriott that we can provide all the discounts in the world

are they still clients if you're offering them a discount on your blackmail demands?

Re: clients

chivo243

Yes, yes they are. Both parties have leverage. As a client, my ex-boss used to "ghost" some vendors for a certain period, and then call back with gripes and concerns and get a reduction, sucks you have to drop to that level to get a fair price for work. Some guys have the stones to play hardball...

Re: clients

Valeyard

the keyword was "blackmail" though, they never entered into a contract, they're more what you'd call a "victim" in this (a situation partially of their own making perhaps given their history, but still).

No doubt this being in the news at all was what they were threatening them with when asking for the ransom

"Be there. Aloha."
-- Steve McGarret, _Hawaii Five-Oh_