Marriott International says that a breach of its Starwood guest reservation database exposed the personal information of up to 500 million people. If your information was exposed, there are steps you can take to help guard against its misuse.
According to Marriott, the hackers accessed people’s names, addresses, phone numbers, email addresses, passport numbers, dates of birth, gender, Starwood loyalty program account information, and reservation information. For some, they also stole payment card numbers and expiration dates. Marriott says the payment card numbers and some passport numbers were protected but not encrypted.
The hotel chain says the breach began in 2014 and anyone who made a reservation at a Starwood property on or before September 10, 2018 could be affected. Starwood brands include W Hotels, St. Regis, Sheraton Hotels & Resorts, Westin Hotels & Resorts, Le Méridien Hotels & Resorts, and other hotel and timeshare properties.
The company set up an informational website and a call center, 877-273-9481, to answer questions. It says affected customers also can sign up for a year of free services that will monitor websites that criminals use to share people’s personal information. Marriott says the service will alert customers if their information shows up on the websites, and will also include fraud loss reimbursement and other services.
If your information was exposed, take advantage of the free monitoring service, and consider taking these additional steps:
- Check your credit reports from Equifax, Experian, and TransUnion — for free — by visiting annualcreditreport.com. Accounts or activity that you don’t recognize could signal identity theft. Visit IdentityTheft.gov to find out what to do.
- Review your payment card statements carefully. Look for credit or debit card charges you don’t recognize. If you find fraudulent charges, contact your credit card company or bank right away, report the fraud, and request a new payment card number.
- Place a fraud alert on your credit files. A fraud alert warns creditors that you may be an identity theft victim and that they should verify that anyone seeking credit in your name really is you. A fraud alert is free and lasts a year.
- Consider placing a free credit freeze on your credit reports. A credit freeze makes it harder for someone to open a new account in your name. Keep in mind that it won’t stop a thief from making charges to your existing accounts.
Marriott says it will send some customers emails with a link to its informational website. Often, phishing scammers try to take advantage of situations like this. They pose as legitimate companies and send emails with links to fake websites to try to trick people into sharing their personal information. Marriott says its email will not have any attachments or request any information.
To learn more about protecting yourself after a data breach, visit IdentityTheft.gov/databreach.
This blog post was updated on June 13, 2024 to reflect that in April 2024 Marriott revealed that payment card numbers and some passport numbers exposed in the breach were protected but not encrypted.
In reply to Thank you for this by ken
In reply to Really? One of the largest by really?
Was your information exposed? Marriott has an informational website and a call center, 877-273-9481, to answer questions. Marriott says affected customers can sign up for a year of free services that will monitor websites that criminals use to share people’s personal information. It says the service will alert customers if their information shows up on the websites, and will also include fraud loss reimbursement and other services.
If your information was exposed, take advantage of the free monitoring service, and consider taking the additional steps described in the blog.
In reply to Was your information exposed? by FTC Staff
In reply to The fact that this happened 4 by freakedout
If your information was exposed, take advantage of the free monitoring. Marriott has an informational website and a call center, 877-273-9481, to answer questions. Marriott says affected customers can sign up for a year of free services that will monitor websites that criminals use to share people’s personal information. It says the service will alert customers if their information shows up on the websites, and will also include fraud loss reimbursement and other services.
Consider the additional steps listed in the blog. They can help you spot identity theft and stop someone from opening accounts in your name.
In reply to If your information was by FTC Staff
In reply to I believe virtually all fraud by YKR
In reply to I received an email sending a by Concerned
That's a scam email - delete it! Thank's for spotting that and warning people.
It's good that you didn't click on the links or reply to it. That email is from a scammer who is phishing around for information. Scammers often send emails like that after a breach. They hope people will click on the links and share personal information.
In reply to I got the "We're sorry. Here by Everyone is th…
In reply to Anyone else receiving tons of by StarwoodBreached
In reply to Anyone else receiving tons of by StarwoodBreached
In reply to Yes, I am literally bombarded by StarwoodBreachedToo
In reply to It is May and the emails by Me too