The California Office of the Attorney General reported on November 20, 2015, that Starwood Hotels & Resorts experienced a malware intrusion affecting some point of sale systems at a limited number of hotels in North America. The breach allowed unauthorized access to payment card data, including cardholder names, numbers, security codes, and expiration dates. The specific number of individuals affected and exact breach dates are unknown.
Source: https://oag.ca.gov/ecrime/databreach/reports/sb24-58971
TPRM report: https://www.rankiteo.com/company/starwoodhotels
"id": "sta249072825",
"linkid": "starwoodhotels",
"type": "Breach",
"date": "11/2015",
"severity": "60",
"impact": "2",
"explanation": "Attack limited on finance or reputation"
{'affected_entities': [{'industry': 'Hospitality',
'location': 'North America',
'name': 'Starwood Hotels & Resorts',
'type': 'Hospitality'}],
'attack_vector': 'Point of Sale Systems',
'data_breach': {'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Payment Card Data'},
'date_publicly_disclosed': '2015-11-20',
'description': 'The California Office of the Attorney General reported on '
'November 20, 2015, that Starwood Hotels & Resorts experienced '
'a malware intrusion affecting some point of sale systems at a '
'limited number of hotels in North America. The breach allowed '
'unauthorized access to payment card data, including '
'cardholder names, numbers, security codes, and expiration '
'dates. The specific number of individuals affected and exact '
'breach dates are unknown.',
'impact': {'data_compromised': ['Cardholder Names',
'Card Numbers',
'Security Codes',
'Expiration Dates'],
'payment_information_risk': 'High',
'systems_affected': 'Point of Sale Systems'},
'initial_access_broker': {'entry_point': 'Point of Sale Systems'},
'motivation': 'Financial Gain',
'references': [{'date_accessed': '2015-11-20',
'source': 'California Office of the Attorney General'}],
'title': 'Starwood Hotels & Resorts Malware Intrusion',
'type': 'Malware Intrusion'}