• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechCyber Saturday

Cyber Saturday—Marriott’s Data Breach Baloney, Quora Hack, Aussie Encryption Law

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
December 8, 2018, 6:30 PM ET

Happy weekend, Cyber Saturday readers.

I’m back stateside after a week-and-a-half stay in China, where I helped host Fortune‘s 2018 Global Tech Forum. I hope you understand the absence of last weekend’s dispatch; following the event, I took an impromptu vacation in Hong Kong. Thankfully, I did not stay at a Marriott hotel. Speaking of which.

As you have no doubt heard by now, Marriott disclosed a massive data breach that exposed up to 500 million customer records. Hackers accessed information in the company’s Starwood reservation system, which affected brands such as W Hotels, St. Regis, Sheraton Hotels & Resorts, Westin Hotels & Resorts, and other properties in the Starwood portfolio, the company said. The intrusion apparently began in 2014, two years before Marriott acquired Starwood. This oversight in the M&A process calls to mind another recent, post-acquisition hacker-surprise: Yahoo, whose two mega-breaches remained undetected when the company sold to Verizon last year. Coincidentally, Marriott’s hack is the biggest suffered by a corporation, second only to those at Yahoo.

After news of the Marriott breach came out, Sen. Charles E. Schumer (D-N.Y.) called on the hotel chain to foot the bill and replace people’s passports which were potentially compromised as part of the breach. Marriott quickly promised to cover the cost for as many as 327 million people whose passport numbers may have been exposed. At a fee of $110 per passport, that would put Marriott on the hook to pay up to $36 billion—a price tag equivalent to the value of the entire company, per its market capitalization. A devastating payout.

Here’s the thing though: While seemingly noble, Marriott’s promise is a bunch of baloney. The company said it will follow through on reimbursement only in instances where it “determine[s] that fraud has taken place.” What this caveat conveniently excludes is that Marriott’s hack likely had little to do with fraud and everything to do with espionage. In other words, if you’re a victim, don’t expect remuneration.

As Reuters reported, investigators believe the perpetrators of this attack were Chinese spies. The breach used tools, tactics, and procedures that matched Beijing’s style. The intrusion is said to have begun shortly after a breach of the government’s Office of Personnel Management, which government officials have attributed to China. The Starwood database represents a massive trove of potential intelligence: information on who is staying where, when—a bonanza for building up profiles of targets and tracking people of interest.

Geng Shuang, China’s Ministry of Foreign Affairs spokesperson, issued a statement saying the country “opposes all forms of cyber attack,” per Reuters. He said the country would investigate the claims, if offered evidence. Meanwhile, Connie Kim, a Marriott spokesperson, said “we’ve got nothing to share” about the Chinese attribution claim.

The Marriott breach—which took place quietly over years, as spies prefer—does not appear to have been a cybercriminal score. The passport payment pledge is probably bunk; nevertheless, if you think you might have been affected, it won’t hurt to follow these steps to refresh your cybersecurity hygiene and better protect yourself.

Have a great weekend.

Robert Hackett

@rhhackett

robert.hackett@fortune.com

Welcome to the Cyber Saturday edition of Data Sheet, Fortune’s daily tech newsletter. Fortune reporter Robert Hackett here. You may reach Robert Hackett via Twitter, Cryptocat, Jabber (see OTR fingerprint on my about.me), PGP encrypted email (see public key on my Keybase.io), Wickr, Signal, or however you (securely) prefer. Feedback welcome.

THREATS

Encryption down under. The Australian government passed into law a piece of legislation that would require tech companies to provide law enforcement access to users' encrypted communications. Cybersecurity pros say the new law will open people's communications up to spies and hackers.

Q: Who got hacked? Answer: Quora, the Q&A website. The company said data for about 100 million user accounts were compromised, including usernames, email addresses, password hashes, and more. Quora said about 300 million people use the website each month.

GOP infiltrator. During this year's midterm elections, the email accounts of four senior aides at the National Republican Congressional Committee were surveilled by an intruder, Politico reported. Officials said they did not disclose the breach "because they were intent on conducting their own investigation and feared that revealing the hack would compromise efforts to find the culprit."

Symantec shakeup. Three top-level executives have recently left the cybersecurity giant: Michael Fey, chief operating officer and president; Michael Williams, chief marketing officer; and Bradon Rogers, head of "go-to-market" teams. In their absence, other executives are taking on expanded duties. Meanwhile, Symantec recently wrapped an investigation that found it had misreported financial earnings, recognizing millions of dollars in revenue in a wrong quarter.

Here are the only 2019 cybersecurity predictions worth reading.

Share today's Cyber Saturday with a friend:

http://fortune.com/newsletter/cybersaturday/

Looking for previous Data Sheets? Click here

ACCESS GRANTED

Invasion of the privacy snatchers. An essay recently published by the Niskanen Center, a Washington, D.C.-based think tank that promotes a libertarian agenda, argues against "privacy fundamentalism": the ideological rejection of any privacy-intrusive technologies without consideration of their potential value to consumers. In the piece, Alec Stapp, the author and a technology policy fellow at the center, critically examines a trend he calls the "privacy panic cycle," which he says tends to exaggerate the risks of new technologies. (See the backlash over Caller ID in the early '90s.) Here's an excerpt.

Many new technologies go through this “privacy panic cycle” (e.g., RFID tags, cameras, loyalty cards). It often begins with advocacy groups — such as the Electronic Privacy Information Center (EPIC), the Center for Democracy & Technology (CDT), Access Now, and others — feeding the natural tendency of media outlets to exaggerate the risks associated with a new technology because audiences love negative news (“if it bleeds, it leads”). As the frenzy escalates, headlines start to declare that the sky is falling. Then, despite the Chicken Little omens, fears begin to diminish over time as reality sets in. The cycle ends — not with a bang, but a whimper — as consumer appreciation of the new technology or service proves the deciding factor in its ultimate widespread adoption.

My favorite bit, not included above, analyzes the unlikely coalition formed between groups motivated by "both virtuous and venal interests," called "bootleggers and Baptists." That section is well worth a read.

FORTUNE RECON

In the Wake of GDPR, Will the U.S. Embrace Data Privacy? by David Meyer

How the iPhone's Health App Caught a Man Jailed for Murdering Wife by Don Reisinger

FCC Chair Ajit Pai Admits Millions of Russian and Fake Comments Distorted Net Neutrality Repeal by Glenn Fleishman

Speak Up: Pindrop Raises $90 Million to Expand Voice Security by Jeff John Roberts

Google's 'Filter Bubble' Can Manipulate Your Search Results, Study Suggests by Natasha Bach

How Email Scammers Are Using Marketeer Methods to Target CFOs by David Meyer

Khashoggi Friend Sues Israeli Spyware Firm Over the Journalist's Murder by Erik Sherman

ONE MORE THING

Save the children. Big Tech companies are getting their hands on the data of children thanks to over-sharing parents and surveillance-friendly technologies, like home security cameras, smart speakers, Internet-connected toys, and gaming apps. In a report released in November, Anne Longfield, England's children's commissioner, estimated that children on average have 70,000 posts about themselves online by their 18th birthday. "We need to stop and think about what this means for children’s lives now and how it may impact on their future lives as adults," Longfield argues. (HT to Vox for covering the report.)

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Sam Altman walks inside a courthouse
LawOpenAI
Sam Altman defends himself as a ‘honest and trustworthy businessperson’ in trial testimony detailing his past dealings with Elon Musk
By The Associated Press, Barbara Ortutay and Matt O'BrienMay 12, 2026
10 hours ago
An employee pulls out a server rack shelf at the rear of a Trainium3 UltraServer at an Amazon Web Services QA lab in Austin, Texas, on February 3, 2026.
AIAmazon
‘That doesn’t sound very healthy’: Amazon’s reported tokenmaxxing might gamify AI usage, analyst warns
By Eva RoytburgMay 12, 2026
10 hours ago
amazon
RetailAmazon
Amazon’s promise of 30-minute delivery collides with memories of Domino’s drivers crashing in the late 1980s
By Anne D'Innocenzio and The Associated PressMay 12, 2026
10 hours ago
robot
AIRobots
This South Korean hotel worker is training a robot to fold a banquet napkin: ‘I’ve been doing this about once a month’
By Kim Tong-Hyung and The Associated PressMay 12, 2026
10 hours ago
DHS wants to build AI smart glasses using the facial recognition tech ICE agents already ‘could be’ using on Americans
LawMeta
DHS wants to build AI smart glasses using the facial recognition tech ICE agents already ‘could be’ using on Americans
By Catherina GioinoMay 12, 2026
11 hours ago
turner
CommentaryMedia
Ted Turner built the original infinite scroll. The attention economy is running on his playbook 
By Nick LichtenbergMay 12, 2026
12 hours ago

Most Popular

The Bezos family just donated $100 million to help achieve one of Mayor Zohran Mamdani’s top campaign promises
Politics
The Bezos family just donated $100 million to help achieve one of Mayor Zohran Mamdani’s top campaign promises
By Jake AngeloMay 12, 2026
11 hours ago
Forget U.S. debt, China's total borrowing is in 'a league of its own'—much worse and deteriorating faster, analyst says
Economy
Forget U.S. debt, China's total borrowing is in 'a league of its own'—much worse and deteriorating faster, analyst says
By Jason MaMay 11, 2026
2 days ago
U.S. hotels are calling the World Cup a 'non-event' and 80% warn bookings are falling short of expectations, report finds
North America
U.S. hotels are calling the World Cup a 'non-event' and 80% warn bookings are falling short of expectations, report finds
By Sasha RogelbergMay 12, 2026
23 hours ago
Nearly 50,000 Lake Tahoe residents have to find a new power source after their energy source looks to redirect lines to data centers
Travel & Leisure
Nearly 50,000 Lake Tahoe residents have to find a new power source after their energy source looks to redirect lines to data centers
By Catherina GioinoMay 12, 2026
14 hours ago
Microsoft’s CFO admits she joined the tech giant without even knowing her salary—and then missed her first day of work
Success
Microsoft’s CFO admits she joined the tech giant without even knowing her salary—and then missed her first day of work
By Preston ForeMay 11, 2026
2 days ago
OpenAI CEO Sam Altman says Gen Z and millennials are using ChatGPT like a 'life advisor'—but college students might be one step ahead
Tech
OpenAI CEO Sam Altman says Gen Z and millennials are using ChatGPT like a 'life advisor'—but college students might be one step ahead
By Sydney LakeMay 10, 2026
3 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.