Credential theft
Marriott International 2020 Breach β 5.2 Million Guests via Employee Credentials
Primary Source βIncident Details
In March 2020, Marriott International disclosed a second data breach (separate from the 2018 Starwood breach affecting 383 million guests) in which an attacker used the login credentials of two employees at a franchise property to access a Marriott guest services application. The breach occurred at some point before late January 2020 and was discovered on 31 January 2020 when Marriott was alerted to the unexpected data access. The attacker had access to the application from approximately January to late January 2020. Approximately 5.2 million guest accounts were accessed. Exposed data included names, addresses, email addresses, phone numbers, loyalty account numbers and points balances, birth dates, gender, communication preferences, company affiliations, room preferences, and language preferences. Encrypted payment card information and passwords were not compromised. Marriott contacted all affected guests and notified regulators worldwide. The UK ICO was notified and investigated (Marriott had ongoing engagement with the ICO following the larger 2018 breach). Marriott offered free identity monitoring services to affected guests. The breach raised questions about multi-factor authentication for employee access to sensitive guest data systems and the ability to detect anomalous access patterns β particularly when access was through legitimate employee credentials.
Technical Details
- Initial Attack Vector
- An attacker used the login credentials of two Marriott employees at a franchise property to access a Marriott application used to provide services to guests; the attacker accessed guest data through the legitimate employee login for approximately two months before detection
- Vendor / Product
- Marriott guest services application
Timeline
- 2020-01-01 Breach occurred
- 2020-03-31 Publicly disclosed
- 2020-03-31 Customers notified