Marriott Reveals Five Million Passport Numbers Stolen in Starwood Breach

Marriott reduces its estimated breach victim count to fewer than 383 million guests but confirms the theft of over five million unencrypted passport numbers.

Marriott revises its estimate of affected customers in the Starwood data breach downward from 500 million to fewer than 383 million unique guests. The hotel giant states that it still cannot provide a more precise number of victims whose information is actually compromised. This updated figure comes as part of an ongoing investigation into one of the largest and most damaging hacking incidents in recent memory.

The situation takes a darker turn as Marriott confirms that hackers steal more than five million unencrypted passport numbers, alongside over 20 million encrypted passport numbers. This highly sensitive data poses severe risks for identity theft and presents a significant threat to government officials and diplomats, as spy agencies highly value passport logs to track clandestine activities. Additionally, the breach exposes 8.6 million unique payment card numbers, though only 354,000 of those cards remain active and unexpired.

Marriott claims it has no evidence that the hackers obtained the keys needed to decrypt the encrypted passport data, though it does not explain how it reaches this conclusion. To prevent further compromise, the company completes the phase-out of the vulnerable Starwood guest reservation database and successfully migrates all bookings to its secure Marriott system.

Read More at the original source →