The information of as many as 500 million people staying at Starwood hotels has been compromised and Marriott says it’s uncovered unauthorized access that’s been taking place within its Starwood network since 2014.
The company said Friday that credit card numbers and expiration dates of some guests may have been taken.
For about 327 million people, the information exposed includes some combination of name, mailing address, phone number, email address, passport number, Starwood Preferred Guest account information, date of birth, gender, arrival and departure information, reservation date and communication preferences.
For some guests, the information was limited to name and sometimes other data such as mailing address, email address or other information.
Marriott said that there was a breach of its database in September, which had guest information related to reservations at Starwood properties on or before Sept. 10.
Starwood operates hotels under the names: W Hotels, St. Regis, Sheraton Hotels & Resorts, Westin Hotels & Resorts, Element Hotels, Aloft Hotels, The Luxury Collection, Tribute Portfolio, Le Méridien Hotels & Resorts, Four Points by Sheraton and Design Hotels. Starwood branded timeshare properties are also included.
Marriott International Inc. discovered through the investigation that someone copied and encrypted guest information and tried to remove it.
Marriott and Starwood merged two years ago and attempts to combine the loyalty programs for the hotels have been marred by technical difficulties.
CEO Arne Sorenson said in a prepared statement Friday that Marriott is still trying to phase out Starwood systems.
Marriott has set up a website and call centre for anyone who thinks that they are at risk, and on Friday will begin sending emails to those affected.
Shares of Marriott tumbled 6 per cent before the opening bell.
The Associated Press