New: Check If You W...
 

New: Check If You Were Impacted By The Marriott Data Breach

12 Posts
6 Users
0 Reactions
192 Views
Posts: 39833
Admin
Topic starter
(@lucky)
Member
Joined: 13 years ago
[#9025]
wpf-cross-image

In late November 2018, Marriott revealed the details of a massive data breach. This involved Starwood’s guest reservations system, with an unauthorized party potentially copying and encrypting information all the way from 2014 until September 10, 2018. At the time Marriott said that they believed this could contain information for up to 500 million guests,…

Continue reading: New: Check If You Were Impacted By The Marriott Data Breach

Share your questions, experiences, and thoughts below.


11 Replies
11 Replies
(@matt-db)
Joined: 5 years ago

Member
Posts: 0

Hard pass


Reply
(@Luke H)
Joined: 10 years ago

Posts: 38

Marriott says data on “fewer than 383 million unique guests” was stolen in the data breach. In comparison, the population of the US is 325.7 million. Hrmmmmm. And now they want you to hand over your info again, this time to a third party that won’t even give you an immediate confirmation if you were affected? And to what end? It’s not like Marriott is helping, unless you get victimized first.


Reply
 Will
(@Will)
Joined: 8 years ago

Posts: 2

And then the so-called security firm release a statement that their database has been hacked 1 month later. LOL


Reply
(@Christian)
Joined: 8 years ago

Posts: 1

Passport number is optional.


Reply
 John
(@John)
Joined: 15 years ago

Posts: 78

Marriott gave members a one-year subscription to a credit monitoring/security firm, which has already let me know some time ago what, of my information, has indeed been compromised.

Right, royal PITA to fix, and to continue keeping track of, for sure.

For any that may have moved in the last year, the form doesn't clarify if address information entered is to be current, or that in place at the time of the breach (this situation probably only applies to a few, but...)


Reply
 Pat
(@Pat)
Joined: 12 years ago

Posts: 8

Thanks for this link. Anyone know which SPG account number to use? The one prior to the merger or the one assigned to us from Marriott after combining accounts?


Reply
Diamond
(@andrew-5)
Joined: 5 years ago

Member
Posts: 740

Hard pass here, as well.

Look: you've been compromised regardless. If you shopped anywhere online, it's just inevitable because we have near-zero legal protection for consumer identity.

If HIPAA punishments applied to for-profit organizations, then you would see change. Until then, you're already compromised. Get in line for your free credit protection. (...or not. Thanks Marriott.)


Reply
Diamond
(@robert-hanson)
Joined: 5 years ago

Member
Posts: 0

They may have only announced this in Nov 18, but the breach was way before then, they just didn't tell us about it when it happened. I'd guess if you were "affected" by this, you would have seen the consequences by now on your own.


Reply
(@mahjong)
Joined: 12 years ago

Posts: 34

Last 6 characters of Passport Number are optional but recommended. IMHO it is absurd to provide any information of a sensitive nature such as characters from a Passport Number after such a massive data breach.


Reply
 Joe
(@Joe)
Joined: 10 years ago

Posts: 749

I'm guessing this company paid Marriott to do this service so that they can curate your data and sell it. There is zero reason why Marriott can't provide this service simply via your membership number. Providing all your personal info clearly is because this company has no access to your data but by you providing it you're giving them free info and who knows how accurate it even is.


Reply
 Todd
Diamond
(@todd-scheven)
Joined: 5 years ago

Member
Posts: 320

What an absolute cluster.

They publish a form that is right out of the "Phishing for Dummies" and "Phishing 101" handbooks.

Here's the position everyone needs to take: Assume breach.

Act accordingly.


Reply