Marriott says 25 million passport numbers, some unencrypted, involved in massive breach

Marriott International said Friday that 383 million customer records were stolen in a data breach last month, down from the hotel chain’s original estimate of 500 million. Roughly 25.5 million passport numbers also were compromised in the data breach affecting Starwood Hotels reservation system, the company said in a statement. Hackers spent roughly four years inside Starwood’s networks, the company announced Nov. 30. The breach is the one of the largest ever reported and is under investigation by at least five U.S. states as well as European regulators. Some 5.25 million of the 25.5 million passports numbers were stored in plain text, Marriott said Friday, providing hackers with a valuable means of stealing individuals’ identities. The hotel chain previously said it would compensate customers for passport replacements if they can prove they had been victims of fraud. The company also said it believes that approximately 8.6 million encrypted payment cards […]

The post Marriott says 25 million passport numbers, some unencrypted, involved in massive breach appeared first on CyberScoop.

Continue reading Marriott says 25 million passport numbers, some unencrypted, involved in massive breach

Marriott Breach, Lame Printer Hack, and Docker – Paul’s Security Weekly #585

This week, how Docker containers can be exploited to mine for cryptocurrency, WordPress sites attacking other WordPress sites, why the Marriott Breach is a valuable IT lesson, malicious Chrome extensions, why hospitals are the next frontier of cybersec… Continue reading Marriott Breach, Lame Printer Hack, and Docker – Paul’s Security Weekly #585

The Quora Data Breach, Facebook’s Private Emails, Google Location Tracking – WB46

https://youtu.be/0O3rruiS6Z0 This is your Shared Security Weekly Blaze for December 10th 2018 with your host, Tom Eston. In this week’s episode: In this week’s episode: the Quora data breach, Facebook’s private emails, and Google loca… Continue reading The Quora Data Breach, Facebook’s Private Emails, Google Location Tracking – WB46

Smashing Security #107: Sextorting the US army, and a Touch ID scam

Fitness apps exploit TouchID through a sneaky user interface trick, tech giants claim to have a plan to banish passwords, and you won’t believe who was behind a sextortion scam that targeted over 400 members of the US military.
All this and much much m… Continue reading Smashing Security #107: Sextorting the US army, and a Touch ID scam

Marriott: The Case for Cybersecurity Due Diligence During M&A

If ever there was a perfectly packaged case study on data breaches, it’s Marriott’s recently disclosed megabreach. Last week, the hotel chain announced that its Starwood guest reservation system was hacked in 2014—two years before Ma… Continue reading Marriott: The Case for Cybersecurity Due Diligence During M&A