Marriott’s massive data breach exposed more than just 500 million customer records, it is also shining a light on the role cybersecurity needs to play when a firm is in acquisition mode, along with the damage that even one slip up by an employee can have on the entire company.

Marriott has not disclosed exactly how cybercriminals managed to enter the Starwood reservation system compromising 500 million records, but the early action on the breach is leaning toward the malicious actors obtaining employee credentials in some manner and gaining access to the system. And since their presence was in place two years before Marriott’s purchase of Starwood Hotels there was an obvious omission by Marriott during its vetting process of Starwood and its computer network.

The general consensus is the breach did not involve a hack using malware, but a few other possibilities have been broached. Ben Johnson, co-founder and CTO of Obsidian Security, thinks the attacker originally gained entry through an employee error.

Please register to continue.

Already registered? Log in.

Once you register, you'll receive:

  • News analysis

    The context and insight you need to stay abreast of the most important developments in cybersecurity. CISO and practitioner perspectives; strategy and tactics; solutions and innovation; policy and regulation.

  • Archives

    Unlimited access to nearly 20 years of SC Media industry analysis and news-you-can-use.

  • Daily Newswire

    SC Media’s essential morning briefing for cybersecurity professionals.

  • Learning Express

    One-click access to our extensive program of virtual events, with convenient calendar reminders and ability to earn CISSP credits.