万豪数据库被黑 华住之后万豪酒店顾客数据遭黑客泄露

2018-11-30 23:13来源:99科技综合编辑:顾小北

扫一扫

分享文章到微信

扫一扫

关注99科技网微信公众号

    原标题:万豪数据库被黑 华住之后万豪酒店顾客数据遭黑客泄露

    11月30日晚间消息,万豪国际酒店集团(Marriott International)刚刚宣布,旗下喜达屋酒店(Starwood Hotel)的一个顾客预订数据库被黑客入侵,可能有约5亿顾客的信息泄露。

  该消息公布后,万豪国际酒店股价在今日盘前交易中一度下跌逾5%。

  万豪国际酒店称,调查结果显示,有一未授权方复制并加密了这些数据。而且,自2014年就开始了对喜达屋酒店网络进行未授权访问。


  目前,万豪国际酒店已采取了补救措施,但并未公布进一步的信息。

  万豪国际酒店称,这些可能被泄露的信息包括顾客的姓名、通信地址、电话号码、电子邮箱、护照号码、喜达屋VIP客户信息、出生日期、性别和其他一些个人信息。

  对于部分客户,可能被泄露的信息还包括支付卡号码和有效日期,但这些数据是加密的。

  万豪国际酒店表示,已将该事件报告给执法部门和监管部门,积极配合其调查。

  www.51hacking.com渗透测试培训

  以下是全文信息:

  Hackers have had access to the Starwood guest reservation database since 2014.

  Marriott said forensic experts managed to decrypt the data attackers stole from the Starwood guest reservation database earlier this month, on November 19.

  They said the attackers exfiltrated information on up to approximately 500 million guests who made a reservation at a Starwood property.

  The Starwood hotel chain, which Marriott acquired in 2016, includes other hotel brands, such as W Hotels, St. Regis, Sheraton Hotels & Resorts, Westin Hotels & Resorts, Element Hotels, Aloft Hotels, The Luxury Collection, Tribute Portfolio, Le Méridien Hotels & Resorts, Four Points by Sheraton and Design Hotels.

  Investigators said that for 327 million of the Starwood guests, the information that attackers stole included a name, mailing address, phone number, email address, passport number, Starwood Preferred Guest ("SPG") account information, date of birth, gender, arrival and departure information, reservation date, and communication preferences.

  For some of these guests, payment card data was also stolen, but Marriott did not say for how many.

  "For some, the information also includes payment card numbers and payment card expiration dates, but the payment card numbers were encrypted using Advanced Encryption Standard encryption (AES-128)," the hotel said today in an SEC filing.

  "There are two components needed to decrypt the payment card numbers, and at this point, Marriott has not been able to rule out the possibility that both were taken," the hotel chain added.

  For the rest, up to 500 million, the data only included a name, and sometimes other info such as mailing address, email address, or other information.

  Marriott started today notifying all affected guests via email. Hotel guests will also be able to visit a website that will be available later today at info.starwoodhotels.com for information about the incident. Where eligible, some users will also be able to enroll in a free identity monitoring service.

  "We deeply regret this incident happened," said Arne Sorenson, Marriott's President and Chief Executive Officer. "We fell short of what our guests deserve and what we expect of ourselves. We are doing everything we can to support our guests, and using lessons learned to be better moving forward."

  "Today, Marriott is reaffirming our commitment to our guests around the world. We are working hard to ensure our guests have answers to questions about their personal information, with a dedicated website and call center. We will also continue to support the efforts of law enforcement and to work with leading security experts to improve. Finally, we are devoting the resources necessary to phase out Starwood systems and accelerate the ongoing security enhancements to our network," Sorenson added.

  This is the third breach affecting Marriott's Starwood chain after the infections with Point-of-Sale (PoS) malware disclosed in 2015 and again in 2016.

     投稿邮箱:jiujiukejiwang@163.com   详情访问99科技网:http://www.99it.com.cn

相关推荐
安全软件公司 McAfee 以 140 亿美元被收购 创始人已 安全软件公司 McAfee 以 140 亿美元被收购 创始人已

原标题:安全软件公司 McAfee 以 140 亿美元被收购 创始人已于 6 月身亡 安全软件

网络安全2021-11-09

剁手族请注意!被“双十一”促销垃圾短信轰炸 剁手族请注意!被“双十一”促销垃圾短信轰炸

原标题:剁手族请注意!被双十一促销垃圾短信轰炸 可拨这个电话举报 11月1

网络安全2021-11-07

Facebook被指已经意识到存在于其用户中的“问题使 Facebook被指已经意识到存在于其用户中的“问题使

原标题:Facebook被指已经意识到存在于其用户中的问题使用 据了解,《华尔街日

网络安全2021-11-07

GitLab 服务器漏洞被滥用于发起超过 1Tbps 的 DDoS GitLab 服务器漏洞被滥用于发起超过 1Tbps 的 DDoS

原标题:GitLab 服务器漏洞被滥用于发起超过 1Tbps 的 DDoS 攻击 Google 云安全可靠

网络安全2021-11-06

重磅!微信、淘宝等或迎超级监管:隐私、垄断 重磅!微信、淘宝等或迎超级监管:隐私、垄断

原标题:重磅!微信、淘宝等或迎超级监管:隐私、垄断等行为被严控 国内移

网络安全2021-10-30

元气森林再陷“被薅羊毛”风波:系运营事故 或 元气森林再陷“被薅羊毛”风波:系运营事故 或

原标题:元气森林再陷被薅羊毛风波:系运营事故 或损失200万 元气森林再陷被

网络安全2021-10-27

25岁女子假扮“大粉”诈骗被逮捕 13名饭圈女孩损 25岁女子假扮“大粉”诈骗被逮捕 13名饭圈女孩损

原标题:25岁女子假扮大粉诈骗被逮捕 13名饭圈女孩损失超十万 25岁女子营造大

网络安全2021-10-26

NO作no死!运用AI去除马赛克贩卖敏感视频 日本男 NO作no死!运用AI去除马赛克贩卖敏感视频 日本男

原标题:NO作no死!运用AI去除马赛克贩卖敏感视频 日本男子违反版权法被捕 众

网络安全2021-10-19

辱骂、威胁、连环夺命call……细数那些被“朋友 辱骂、威胁、连环夺命call……细数那些被“朋友

原标题:辱骂、威胁、连环夺命call细数那些被朋友借贷套住的倒霉蛋 人无信不

网络安全2021-10-15

Facebook 严控内部留言板,防止内部机密信息被泄 Facebook 严控内部留言板,防止内部机密信息被泄

原标题:Facebook 严控内部留言板,防止内部机密信息被泄露 10 月 14 日消息,

网络安全2021-10-15