Marriott smacked with $33.7m fine over infamous data breach

June 17, 2018 - Vancouver, BC, Canada: Marriott International is an American multinational diversified hospitality company that manages and franchises a broad portfolio of hotels and related lodging facilities

The United Kingdom’s data privacy watchdog has fined Marriott International £18.4 million (around $33.7 million) for a major data breach that may have affected as many as 339 million guests.

The Information Commissioner’s Office (ICO) said the data obtained by hackers could have included names, email addresses, phone numbers, unencrypted passport numbers, arrival or departure information, and guests’ VIP status and loyalty program membership numbers.

The ICO’s investigation found that there were failures by Marriott to put appropriate safeguards in place, as required by the General Data Protection Regulation (GDPR), but acknowledged that the company had improved.

The precise number of people affected is unclear, but Marriott estimates 339 million guest records worldwide were affected following the cyber-attack in 2014 on Starwood Hotels and Resorts Worldwide Inc.

The attack, from an unknown source, remained undetected until September 2018, by which time the company had been acquired by Marriott.

However, the ICO said there may have been multiple records for an individual guest. Seven million guest records related to people in the UK.

“Personal data is precious and businesses have to look after it,” ICO information commissioner Elizabeth Denham said in a statement.

“Millions of people’s data was affected by Marriott’s failure; thousands contacted a helpline and others may have had to take action to protect their personal data because the company they trusted it with had not.

“When a business fails to look after customers’ data, the impact is not just a possible fine. What matters most is the public whose data they had a duty to protect.”

The ICO acknowledged that Marriott acted promptly to contact customers and the ICO. It also acted quickly to mitigate the risk of damage suffered by customers, the ICO said, and has since instigated several measures to improve the security of its systems.

Marriott International said it does not intend to appeal the decision, but made no admission of liability in relation to the decision or the underlying allegations.

The company added that it “deeply regrets” the incident.

“Marriott remains committed to the privacy and security of its guests’ information and continues to make significant investments in security measures for its systems, as the ICO recognises,” the company said in a statement.

“The ICO also recognises the steps taken by Marriott following discovery of the incident to promptly inform and protect the interests of its guests. Marriott wants to reassure guests that the incident and the ICO’s decision involved only Starwood’s separate network, which is no longer in use.”


Featured image source: iStock/volkan.basar

Latest News

  • Cruise
  • News

Search underway for missing cruiser of Sydney Heads

Carnival Cruise Lines have confirmed a search is underway for a passenger who went overboard P&O Cruises Pacific Adventure about 20 kilometres off Sydney Heads this morning. Pacific Adventure was due to dock at Sydney Harbour at 6am this morning but is now searching the waters after a man went overboard around 4:15am. One passenger told 2GB […]

  • Partner Content

Wendy Wu Tours ‘Wonderlust Sale’ offers the wonders of the world for less

Wendy Wu Tours opens the month of May with some very special deals across its most sought-after destinations. From Japan, China and South Korea to Southeast Asia, Central Asia and across India and Latin America, the ‘Wonderlust Sale’ sees all destinations on sale.  The ‘Wonderlust Sale’ is an offer too good to resist with incredible […]

Partner Content

by Travel Weekly

Travel Weekly
  • Technology

Booking.com launches AI Trip Planner in Australia and New Zealand

Booking.com has announced its AI Trip Planner (Beta) is now available for travellers in Australia and New Zealand, the first markets to launch in Asia Pacific. Until now, AI Trip Planner was only available for US and UK travellers after it was launched in the Booking.com app in June last year. Built using Booking.com’s existing […]

  • Products

Embrace the journey: Traversing the world with the Shokz OpenRun

If you’ve been on the wrong side of a final call in the airport, or missed the stop on rail journey, it might be time to invest in a pair of Shokz OpenRun headphones. Originally marketed as headphones for fitness fanatics, runners or cyclists with a keen to steer clear of a prang with a car, […]

  • Tour Operators
  • Tourism

TTC: Deals are driving up demand for September trips

The latest market research from TTC Tour Brands shows interest in international leisure travel remains high for 2024, with 77 per cent of Australians over 18 still planning trips this year. Notably, 28 per cent of those travellers are eyeing September for their journeys. Europe continues to be the most popular destination, with 68 per […]

  • Aviation

Qantas ‘working urgently’ to fix app data leak

Qantas is looking into customer reports that passengers have this morning been able to access other passengers’ personal information on the airlines app. X user Lachlan posted that he was able log into different accounts every time he opened the app. My @Qantas app logs me in to a different person each time I open […]