• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Marriott Fined £18.4m Over Data Breach

You are here: Home / General Cyber Security News / Marriott Fined £18.4m Over Data Breach
October 30, 2020

The Details Commissioner’s Business (ICO) has fined hotel chain Marriott Intercontinental £18.4m over a facts breach that exposed the information and facts of tens of millions of company globally. 

The UK’s impartial physique set up to uphold details legal rights imposed the money penalty on Marriott for “failing to retain thousands and thousands of customers’ personal data safe.”

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


In November 2018, Marriott reported a facts breach that noticed an believed 339 million visitor data uncovered globally, of which about 7 million associated to UK people. An investigation into the incident disclosed that an unauthorized party experienced been accessing the network of Starwood Accommodations and Resorts All over the world Inc. considering the fact that 2014, copying and encrypting info.

The attack remained undetected right up until September 2018, by which time Starwood had been acquired by Marriott. 

The particular facts involved in the breach differed between people today, but the ICO said that it may have involved names, email addresses, phone numbers, unencrypted passport numbers, arrival/departure information, guests’ VIP position, and loyalty system membership range.

An investigation into the incident by the ICO found that Marriott “failed to place suitable specialized or organizational actions in put to defend the particular info currently being processed on its devices, as demanded by the General Facts Defense Regulation (GDPR).”

Nevertheless, the ICO identified that Marriott was swift to act as soon as the breach had been found out, making contact with clients and the ICO instantly. 

“It also acted rapidly to mitigate the risk of harm suffered by customers, and has due to the fact instigated a variety of steps to make improvements to the security of its methods,” said the commissioner’s office environment.

In July past 12 months, the ICO declared an intention to fantastic Marriott £99m over the info breach for “infringements of the GDPR.”

In a statement released yesterday, the ICO mentioned: “As component of the regulatory system, the ICO thought of representations from Marriott, the ways Marriott took to mitigate the consequences of the incident and the economic influence of COVID-19 on their enterprise before environment a last penalty.”

Though the breach dates again to 2014, the GDPR restrictions only came into effect in May possibly 2018, two several years prior to the UK remaining the European Union.


Some elements of this article are sourced from:
www.infosecurity-journal.com

Previous Post: «Wisconsin Republican Party Allegedly Loses $2.3 Million To Hackers Wisconsin Republican Party allegedly loses $2.3 million to hackers
Next Post: Wroba Mobile Banking Trojan Spreads to the U.S. via Texts Wroba Mobile Banking Trojan Spreads To The U.s. Via Texts»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.