Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Operational Security

// // //
12/13/2018
08:15 AM
Scott Ferguson
Scott Ferguson
News Analysis-Security Now

China Suspected of Massive Marriott Data Breach – Report

A New York Times report finds that investigators believe China-backed attackers pulled off the massive data breach at Marriott, exposing the records of 500 million guests. It's a continuation of the tensions between China and the US.

Cyber spies working for China are suspected of pulling off the massive data breach at Marriott, which involved personal data of 500 million Starwood customers, in an effort to gather intelligence on specific US citizens, according to a published report in the New York Times.

Citing unnamed intelligence and law enforcement sources, the Times reported that attackers working for China's Ministry of State Security were behind the original breach, which occurred in 2014, but was only discovered during the last several weeks. (See Marriott: 500 Million Guest Records Compromised in Data Breach.)

In addition to Marriott, the cyber spies targeted health insurance firms and security clearance files to gather information.

One key piece of evidence that points to China is that passport numbers and information on 327 million Starwood customers were part of the breach. This would allow China to create a database on US citizens that it wanted to track, according to the Times.

(Source: iStock)
(Source: iStock)

"Given that these attacks are most probably interrelated and from the same APT [Advanced Persistent Threat], the suspicion that the Chinese are attempting to build more complete personality, or psychographic, profiles of individuals is further credible and downright scary," Mukul Kumar, chief information security officer and vice president of Cyber Practice at security vendor Cavirin, wrote in an email to Security Now.

"The potential damage is an order of magnitude more than simple hacks based on demographic data, giving a whole new meaning to the term 'life hacking,' " he added.

The Chinese government denies that it orchestrated the Marriott breach.

The Times report comes during a period of growing tension between China and the US on a range of issues, including cyberattacks, industrial espionage and trade issues.

To bolster its argument that China is breaking the rules, the Times reported that the Trump administration plans to declassify intelligence reports, as well as criminal indictments, which show wide-spread spying and cyber espionage campaigns conducted by China.

Over the last month, the US Justice Department charged ten Chinese nationals in an elaborate espionage campaign aimed at stealing designs and intellectual property tied to a new generation of turbofan engines. (See DoJ Charges 10 Chinese Nationals in Elaborate Cyberespionage Case.)

Over the last week, those tensions increased when Canadian authorities detained Huawei CFO Meng Wanzhou at the request of the Justice Department as she attempted to switch planes in Vancouver. The full details of the case against her remain shrouded in secrecy, but Wanzhou is suspected on helping the company violate US sanctions against Iran. (See Unknown Document 748229.)

China is demanding that Wanzhou, who is also the daughter of the company's founder, be allowed to return home. She's now free on bail.

There are no direct ties between the Marriott attack and these other incidents, but there's growing concern of what could happen next, especially with two nations that have an arsenal of cyber weapons at their disposal.

Chris Morales, the head of security analytics at Vectra, which makes automated threat management tools, noted in an email that with more and more data being digitized, these types of attacks, whether from cyber criminals or nation-states, are only going to get bigger.

"Part of the reason hacks are now getting so large is because the volume of data generated on the Internet every single day is so large," Morales explained. "Everything is digital. Just like a user would use a search engine to learn information, a cyber spy would want to search a massive online database for information. The difference is the databases used to gain information in this new form of cyber warfare happen to belong to private companies. Intelligence agencies love big data."

In this specific case, however, Morales noted that identity theft is not the end goal.

"A nation state actor would be far more interested in the intelligence gained on military and government officials who are patrons of the hotels," he added. "The Starwood and Marriott hotel chains have large federal contracts with many high-ranking officials staying at their hotels both domestically and internationally."

Related posts:

— Scott Ferguson is the managing editor of Light Reading and the editor of Security Now. Follow him on Twitter @sferguson_LR.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The 10 Most Impactful Types of Vulnerabilities for Enterprises Today
Managing system vulnerabilities is one of the old est - and most frustrating - security challenges that enterprise defenders face. Every software application and hardware device ships with intrinsic flaws - flaws that, if critical enough, attackers can exploit from anywhere in the world. It's crucial that defenders take stock of what areas of the tech stack have the most emerging, and critical, vulnerabilities they must manage. It's not just zero day vulnerabilities. Consider that CISA's Known Exploited Vulnerabilities (KEV) catalog lists vulnerabilitlies in widely used applications that are "actively exploited," and most of them are flaws that were discovered several years ago and have been fixed. There are also emerging vulnerabilities in 5G networks, cloud infrastructure, Edge applications, and firmwares to consider.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2023-1142
PUBLISHED: 2023-03-27
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use URL decoding to retrieve system files, credentials, and bypass authentication resulting in privilege escalation.
CVE-2023-1143
PUBLISHED: 2023-03-27
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use Lua scripts, which could allow an attacker to remotely execute arbitrary code.
CVE-2023-1144
PUBLISHED: 2023-03-27
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contains an improper access control vulnerability in which an attacker can use the Device-Gateway service and bypass authorization, which could result in privilege escalation.
CVE-2023-1145
PUBLISHED: 2023-03-27
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-DataCollect service, which could allow deserialization of requests prior to authentication, resulting in remote code execution.
CVE-2023-1655
PUBLISHED: 2023-03-27
Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.4.0.