>

Marriott’s Second Breach: 5.2 Million Guest Records Exposed

At the end of March 2020, Marriott disclosed its second major breach in two years: the login credentials of two franchise properties had been abused in late February 2020 to siphon 5.2 million guest records, including names, addresses, phone numbers, birthdays, loyalty details, and in some cases travel itineraries and room preferences. Unlike the 2018 Starwood catastrophe that exposed up to 383 million records, this intrusion was caught and contained within weeks, but it reignited regulatory scrutiny on both sides of the Atlantic. This retrospective covers the intrusion path, the data involved, the disclosure timing, and the aftermath for one of hospitality's biggest names.

Continue ReadingMarriott’s Second Breach: 5.2 Million Guest Records Exposed

Virgin Media 2020: 900,000 People in an Unsecured Marketing Database

On 28 February 2020, Virgin Media confirmed that a marketing database containing the personal details of around 900,000 people had been left insecure and accessible online, discovered not by criminals but by a researcher during unrelated work. The dataset, stored on an unsecured cloud instance, included names, home and email addresses, and phone numbers, and had been reachable for at least ten months. This post explains exactly what was exposed, how the misconfiguration happened, how Virgin Media responded, and what happened next: a textbook non-hack data breach that still required full disclosure, notification, and regulatory scrutiny.

Continue ReadingVirgin Media 2020: 900,000 People in an Unsecured Marketing Database
>