Hackers Behind Breach at Hotel Group Marriott Left Clues Suggesting They Were Working For Chinese Government Intelligence Gathering Operation, Report Says (reuters.com) 41
Marriott said last week that a hack that began four years ago had exposed the records of up to 500 million customers in its Starwood hotels reservation system. Private investigators looking into the breach have found hacking tools, techniques and procedures previously used in attacks attributed to Chinese hackers, Reuters reported, citing three sources who were not authorized to discuss the company's private probe into the attack. From the report: That suggests that Chinese hackers may have been behind a campaign designed to collect information for use in Beijing's espionage efforts and not for financial gain, two of the sources said. While China has emerged as the lead suspect in the case, the sources cautioned it was possible somebody else was behind the hack because other parties had access to the same hacking tools, some of which have previously been posted online.
you mean this guy? (Score:1)
Ok. So you mean this guy: Bruce Hoffmeister. He's been there for over 7 years.
http://news.marriott.com/p/bru... [marriott.com]
https://www.linkedin.com/in/br... [linkedin.com]
Re: (Score:2, Insightful)
So funny. The profile page of that turkey on Marriott's webpage shows this in my browser...
© 1996 - {{today | date:'yyyy'}} MARRIOTT INTERNATIONAL, INC.
No wonder they got hacked.
Re: (Score:1)
Blaming the $current_badguy is just deflecting blame away from where it belongs.
Except when it's "Russians" in which case it's Trump's fault and Marriott is in the clear.
Re: (Score:2)
So we shouldn't pursue the guy that breaks into your house, because you inadvertently left the back door open?
There's room enough for both exploring IT security failings and investigating who it was that broke into those systems. They are not mutually exclusive activities.
Re: (Score:2)
"Marriott got hacked due to the incompetence of their CIO and IT department."
Is it honestly possible to 100% safely lock down a network with PCs in 6500+ publicly accessible locations worldwide where 100k+ hourly employees need constant access?
Its like blaming them for allowing a guest to bring in 7 suitcases loaded with bombs. A determined hacker should be able to break into any network that large and likely compromise some of their data.
Russian hackers (Score:4, Interesting)
What is the probability that they were just Russian hackers pretending to be Chinese hackers?
No need to decide, give them both a time-out (Score:2)
They are both bad actors, just turn off all internet connections to the US from Russia on Thursdays and China on Fridays. And keep expanding the time-out one day a week till the problem goes away. Sure it won't stop hackers from working through other countries, and their would be workarounds with proxies in other countries, but the colossal inconvenience of it as collective punishment for the whole country will spur the state-sponsored attacks to become too costly.
The internet is already heading for Balka
Re: (Score:2)
NSA does this... (Score:1)
Didn't we read about NSA tools that drop Chinese and Russian "clues" into binaries to provide false attribution.
If anything those groups are smart enough to not leave those traces, so this was likely the NSA doing this by my logic.
INFORMATION wants to be FREE! (Score:2)
So what is the actual value of the data? (Score:2)
"That suggests that Chinese hackers may have been behind a campaign designed to collect information for use in Beijing's espionage efforts and not for financial gain, two of the sources said."
Wouldn't it be easier to just buy the data from Marriott?
If it's someone "looking to cash in" on the data, what are an additional 500 Million (guessing that there is a whole lot of repeat customers in this data set) records worth?
Used to be hard to get enough information for single credit cards, nowadays you would prob
Re: (Score:1)
so then who were they REALLY working for? (Score:1)
Marriott’s Security Guy isn't to blame... (Score:2)
Their security guy stayed at a "Holiday Inn Express" last night.... I guess we all now know why...
Dead giveaway (Score:2)
The naughty hackers left electronic tools and devices back and the investigation has determined that they were all 'made in China'.
Re: (Score:1)