You are here: Home » Reuters » News
Business Standard

Exclusive: Clues in Marriott hack implicate China - sources


By Christopher Bing

(Reuters) - behind a massive breach at hotel group left clues suggesting they were working for a intelligence gathering operation, according to sources familiar with the matter.

Marriott said last week that a hack that began four years ago had exposed the records of up to 500 million customers in its reservation system.

Private investigators looking into the breach have found hacking tools, techniques and procedures previously used in attacks attributed to Chinese hackers, said three sources who were not authorized to discuss the company's private probe into the attack.

That suggests that Chinese may have been behind a campaign designed to collect information for use in Beijing's espionage efforts and not for financial gain, two of the sources said.

While has emerged as the lead suspect in the case, the sources cautioned it was possible somebody else was behind the hack because other parties had access to the same hacking tools, some of which have previously been posted online.

Identifying the culprit is further complicated by the fact that investigators suspect multiple hacking groups may have simultaneously been inside Starwood's computer networks since 2014, said one of the sources.

If investigators confirm that was behind the attack, that could complicate already tense relations between and Beijing, amid an ongoing tariff dispute and U.S. accusations of Chinese espionage and the theft of trade secrets.

"firmly opposes all forms of cyber attack and cracks down on them in accordance with law," of told "If offered evidence, the relevant Chinese departments will carry out investigations according to law."

Marriott declined to comment, saying "We've got nothing to share," when asked about involvement of Chinese

Marriott disclosed the hack on Friday, prompting U.S. and UK regulators to quickly launch probes into the case.

Compromised customer data included names, passport numbers, addresses, phone numbers, birth dates and email addresses. A small percentage of accounts included scrambled payment card data, said Kim.

Marriott acquired Starwood in 2016 for $13.6 billion, including the Sheraton, Westin, W Hotels, St. Regis, Aloft, Le Meridien, Tribute, Four Points and hotel brands, forming the world's largest

The hack began in 2014, shortly after an attack on the U.S. government's (OPM) compromised sensitive data on tens of millions of employees, including application forms for security clearances.

recently told reporters he believed was behind the OPM hack, a claim first made by the in 2015.

has strongly denied those charges and also refuted charges that it was behind other hacks.

Former senior FBI told that the Marriott case looked similar to hacks that the was conducting in 2014 as part of its intelligence operations.

"Think of the depth of knowledge they could now have about or who happened to be in a certain city at the same time as another person," said Anderson, who served as FBI until 2015.

"It fits with how the services think about things. It's all very long range," said Anderson, who was not involved in investigating the Marriott case and is now a principal with

Michael Sussmann, a former senior for its computer crimes section, said that the long duration of the campaign was an indicator that the hackers were seeking data for intelligence and not information to use in cyber crime schemes.

"One clue pointing to a government attacker is the amount of time the intruders were working quietly inside the network," he said. "Patience is a virtue for spies, but not for criminals trying to steal credit card numbers."

FBI representatives could not immediately be reached for comment on the evidence linking the attack to China. A said on Friday that the agency was looking into the attack, but declined to elaborate.

(Reporting by Christopher in Washington; Editing by Jim Finkle, and Susan Thomas)

(Only the headline and picture of this report may have been reworked by the Business Standard staff; the rest of the content is auto-generated from a syndicated feed.)

First Published: Thu, December 06 2018. 22:38 IST