The records of 500 million customers of the hotel group Marriott International have been involved in a data breach.
The hotel chain said the guest reservation database of its Starwood division had been compromised by an unauthorised party.
It said an internal investigation found an attacker had been able to access the Starwood network since 2014.
The company said it would notify customers whose records were in the database.
Marriott International bought Starwood in 2016, creating the largest hotel chain in the world with more than 5,800 properties.
Starwood’s hotel brands include W Hotels, Sheraton, Le Méridien and Four Points by Sheraton. Marriott-branded hotels use a separate reservation system on a different network.
Marriott said it was alerted by an internal security tool that somebody was attempting to access the Starwood database. After investigating, it discovered that an “unauthorised party had copied and encrypted information”.
It said it believed its database contained records of up to 500 million customers.
For about 327 million guests, the information included “some combination” of:
- phone number
- email address
- passport number
- account information
- date of birth
- arrival and departure information
It said some records also included encrypted payment card information, but it could not rule out the possibility that the encryption keys had also been stolen.
“We deeply regret this incident happened,” the company said in a statement.
“Marriott reported this incident to law enforcement and continues to support their investigation. The company has already begun notifying regulatory authorities.”