Breach Case Study On Marriott/Starwood Hotel System - - PowerPoint PPT Presentation

breach case study on marriott starwood hotel system 2014
SMART_READER_LITE
LIVE PREVIEW

Breach Case Study On Marriott/Starwood Hotel System - - PowerPoint PPT Presentation

Breach Case Study On Marriott/Starwood Hotel System 2014 2018+ Stephen P. Cutler,PhD spcutler@omnipay.asia We will look at it from a perspective of Confidentiality Integrity Accesibility And


slide-1
SLIDE 1
slide-2
SLIDE 2
slide-3
SLIDE 3
slide-4
SLIDE 4
slide-5
SLIDE 5

Breach Case Study On Marriott/Starwood Hotel System 2014 – 2018+

Stephen P. Cutler,PhD spcutler@omnipay.asia

slide-6
SLIDE 6

We will look at it from a perspective of Confidentiality Integrity Accesibility And Accountability, Compliance, Ethics

slide-7
SLIDE 7

Let’s keep in our minds about:

  • What personal data do you hold?
  • Where is it held?
  • Who has access to it, and what kind of access?
  • When did you collect it?
  • Why did you collect this detail?
  • What level is the data classified at?
  • Is consent well documented?
slide-8
SLIDE 8

Marriott is a great company. Global Warm Great reputation.

slide-9
SLIDE 9

Marriott owns the Starwood System Since 2016.

slide-10
SLIDE 10

The Starwood System consists of: 11 brands; 1,200 properties; On Six Continents

slide-11
SLIDE 11

On 8SEP2018, an internal security tool Alerted Marriott staff to an attempt To access and exfiltrate the database

slide-12
SLIDE 12

Think about that database: Name; Date of birth; Gender; Mailing address; Phone; Email address;

slide-13
SLIDE 13

Think about that data base: Passport information; Arrival/departure data; Preferred Guest information; Communication Preferences.

slide-14
SLIDE 14

Marriott says that perhaps

500 million

Starwood guest records may have been stolen

slide-15
SLIDE 15

The alert was posted on September 8, 2018 Marriott notification and public announcements Are worded to say The breach was “discovered on or before September 10, but may go back to 2014”

slide-16
SLIDE 16

Payment Card data was protected by Advanced Encryption Standard AES-128 But...the decryption components may/may Have been taken as well

slide-17
SLIDE 17

U.S. Senator Charles Schumer says That Marriott ought to cover the cost of New passports for victims

  • $110 x 327 million
  • Basically...”You caused this. You fix it now”
slide-18
SLIDE 18

U.S. Senator Elizabeth Warren Calls for severe penalties for The CEO and other officers personally Basically, “You broke these people’s trust. You go to jail.” U.S. law does not currently have such penalty.

slide-19
SLIDE 19

The company admits “We failed” It has cooperated with law enforcement and regulatory agencies. It has investigated thoroughly, and found that the breach is likely to have begun in 2014, before it bought Starwood

slide-20
SLIDE 20

Marriott Established a website and call center for victim support It has emailed everyone in the database It offers free enrollment in”Webwatcher”

slide-21
SLIDE 21

Marriott faces a “Class Action” law suit Marriott stock share prices fell

5.6%

slide-22
SLIDE 22

to a Forbes report by Thomas Brewster posted on December Marriott had a string of cyber security problems. At least one of those came from a contracted cybersecurity vendor mistake.

slide-23
SLIDE 23

One problem discovered was an easily guessed password for the Starwood Service system; Once “inside” that system, one could Access financial records, I.T. Security Controls AND bookings information

slide-24
SLIDE 24

Investigation and reviews have disclosed that Russian criminals used a Botnet On hacked Starwood Servers

slide-25
SLIDE 25

Based on New York Times and Wall Street Journal reports Other media published items on January 4, 2019 Stating that the hackers may/may have been working for China’s Ministry of State Treasury.

slide-26
SLIDE 26

So, again, in light of the DPA:

  • Who?
  • What?
  • When?
  • Where?
  • Why?
slide-27
SLIDE 27

Any questions?

slide-28
SLIDE 28

Thank you!

Stephen P. Cutler spcutler@omnipay.asia

slide-29
SLIDE 29