Marriott says guests’ names, loyalty account information and other personal details may have been accessed in the second major data breach to hit the company in less than two years.
The company said approximately 5.2 million guests worldwide may have been affected. The information taken may include names, addresses, phone numbers, birthdays, loyalty information for linked companies like airlines and room preferences.
Marriott said it is still investigating but it does not believe credit card information, passport numbers or driving licence information was accessed.
The hotel chain said it noticed an unexpected amount of guest information was accessed at the end of February using the login credentials of two employees at a franchised property. The company said it believes the activity began in mid-January.
Marriott has disabled those logins and is assisting authorities in their investigation. The company did not say whether the employees whose logins were used were suspected.
In November 2018, Marriott announced a massive data breach in which hackers accessed information on as many as 383 million guests. In that case, Marriott said unencrypted passport numbers for at least 5.25 million guests were accessed, as well as credit card information for 8.6 million.
The affected hotel brands were operated by Starwood before it was acquired by Marriott in 2016.
The FBI led the investigation into that data theft, and investigators suspected the hackers were working on behalf of the Chinese Ministry of State Security.
Marriott said on Tuesday it has informed guests of the new data breach. The Maryland-based company is offering affected guests free enrolment in a personal information monitoring service for up to a year.
“Marriott also remains committed to further strengthening its protections to detect and remediate incidents such as this in the future,” the company said in a statement.