Ensuring your security: the Marriott data breach

By
on
November 30, 2018

Today Marriott International announced it had discovered a data security incident involving its Starwood guest reservation database. The hotel group has detected unauthorised access to guest information relating to reservations at Starwood properties since 2014. We take your security very seriously. We want to let you know that our team is already hard at work to identify whether any customers have been affected.If we have reason to believe that you may have been affected, then we will be contacting you shortly.

If you’re concerned because you may have made transactions with Marriott International, we recommend you use the customer support Marriott International has established. You can find more information on the website it has dedicated to this incident, which you can find here.

If you are notified by Marriott International that you have been affected by this breach, please forward this communication to our support team and we will issue you a new card for you for free.

As always, if you have any questions about this, our support team is here to help.

What do we know so far?

Marriott believes that this may have affected the information of up to 500 million guests who made a reservation at a Starwood property.

Starwood brands include: W Hotels, St. Regis, Sheraton Hotels & Resorts, Westin Hotels & Resorts, Element Hotels, Aloft Hotels, The Luxury Collection, Tribute Portfolio, Le Méridien Hotels & Resorts, Four Points by Sheraton and Design Hotels. Starwood branded timeshare properties are also included.

The types of affected data include: name, mailing address, phone number, email address, passport number, Starwood Preferred Guest account information, date of birth, gender, arrival and departure information, reservation date, communication preferences – and most importantly, payment card numbers and expiration dates. Marriott is saying that payment card numbers were encrypted, but they also aren’t ruling out the possibility that the encryption method was compromised:

For some, the information also includes payment card numbers and payment card expiration dates, but the payment card numbers were encrypted using Advanced Encryption Standard encryption (AES-128). There are two components needed to decrypt the payment card numbers, and at this point, Marriott has not been able to rule out the possibility that both were taken.

However, we do know for a fact that all of our current active customers have cards issued after July 2017, when we migrated from Visa to Mastercard, so this would only affect customers with relevant transactions after this date.

What are we doing about it?

We take your security very seriously, and we want to let you know that our team is already hard at work to identify whether any customers have been affected.

We will follow up with all our customers who we believe are affected by this. If you are among those affected, we may cancel and reissue your affected Monese cards – this would come at no expense to you - will however be in touch with you directly before we take this action.

What should you do?

Since other types of data have been potentially accessed (such as names and email addresses), we also recommend that you watch out for any potential phishing scams, spam emails, or any out of the ordinary communications.

Marriott says it has begun sending emails to affected guests whose email addresses are in the Starwood guest reservation database. They have also set up a dedicated call center to answer questions about this incident, which is open seven days a week and is available in multiple languages. If you receive any such communication from Marriott, please forward this to our support team and we will issue a new card for you for free.

Additionally, Marriott is providing its guests with a free year of ‘WebWatcher’. This is a tool that monitors sites where personal information is shared and alerts you if evidence of your personal information is found (however this will only be available to our UK customers).

Marriott International announced that passport details may have been compromised as part of this breach. Your passport details are incredibly sensitive. If Marriott confirms that your passport details have been affected, we recommend that you check with your passport issuer on the steps you should take next.

We take every step possible action to protect your financial details and this has always been central to our business operation. We routinely take proactive measures to ensure that, as much as is possible, your data remains safe and secure. The security of our customers is of utmost importance to us and we will always work to protect you, your details and your finances.

Latest articles

Cyber Monday: Things to remember
Security

Cyber Monday: Things to remember

Cyber Monday has arrived! And it is, as ever, a veritable behemoth of a worldwide sales event, bristling with bargains and a dizzying array of offers, all at low, low prices. It’s all too easy however to get a little disorientated by the mass-induced shopping frenzy, and perhaps a little careless in our singular pursuit of that must-have item we've seen online. This means we can often overlook, or ignore, the warning signs that what we're buying, and where we’re buying from, might not be all it seems.

With this in mind, we thought it would be helpful to list a few tips and tricks – as provided by our Fraud Team – that should help keep you stay safe during the Cyber Monday excess, and help keep your money protected from any dodgy deals. One smart way to stay protected while shopping online is to keep your device optimized and free from security vulnerabilities. Using a tool like CleanMyMac can help by removing junk files, clearing malicious threats, and ensuring your system runs smoothly while you browse. A cluttered or sluggish computer can slow you down and even make you more susceptible to scams, so giving your Mac a quick cleanup before diving into Cyber Monday deals is a simple but effective safety measure.

Lock down the URL

When inputting sensitive information, especially financial information on a purchasing page, make sure the URL starts with ‘https’. The ‘S’ means it’s secure.

Avoid bank transfer buying

Try to use trusted payment sources only. Professional merchants usually will have websites that support a variety of payment options. Fraudsters tend to prefer bank transfers.

Watch out for those ‘hidden’ subscription traps

Have you ever looked at your account to see a recurring charge that you didn't expect and didn't order? A subscription trap occurs when you're purchasing online and you're tricked into buying additional products or services that you don’t need. Many have been stung by these types of subscription traps. Over the coming days, check your balance very closely!

Protect your most valuable asset, your data

When making purchases online, think twice if you’re asked for additional personal and sensitive data. Are you being asked for ID, passport or driving licence numbers? Or even National Insurance numbers? These details are irrelevant to your purchase. Your identity could end up getting ‘stolen’ and used to commit unscrupulous things.

Beware fake “IT Support”

Some scammers can give the impression that the website you’re visiting has ‘frozen’ and urge you to call a support team to fix it. During the phone call, these scammers can masquerade as major computer companies and persuade you into believing that your computer is riddled with viruses. In reality it is not, and you’ve passed over sensitive information unnecessarily.

Buy from trusted sites only

Buying from third-party sellers, including some social media stores, offers no refund policies and are a haven for fraudsters looking to steal your money.

By keeping sight of these basic rules of engagement, there’s no reason why your Cyber Monday shopping bonanza – even if you’re just hunting for a great deal on a new phone – shouldn’t be an easy, secure and rewarding pre-Christmas indulgence.

Introducing the new unlimited Monese Premium plan
Features

Introducing the new unlimited Monese Premium plan

We’re dedicated to providing next-generation financial services to everyone, which is why we offer a range of account options - to suit the various needs of our customers.

First and foremost, we cater to those who simply need a free, fully operational Monese account - one that offers all the essential features you’d expect of a standard bank account. Some of our customers, however, are more active than others, which is why our fixed-fee Plus plan is often a better choice - offering lower rates on currency conversions and cash top-ups.

Unmetered money management is cleared for launch

Now we’re introducing the unlimited Premium plan! Designed with the most heavy-duty Monesers in mind, we’re offering them this fantastic opportunity to enjoy the removal of all transactional fees of all kinds, providing a truly exceptional and frictionless mobile money management experience. For a fixed transparent monthly fee, we’re proud to offer Monese Premium - capping the cost of a completely unmetered financial service. Money management simply doesn’t get any better than this!

A fixed fee that’s simple and fair

The flat fee of £/€ 14.95 a month will allow for genuinely unlimited money management, offering you as many free ATM cash withdrawals as you like. You’ll also enjoy free foreign currency exchange at the wholesale rate, free cash top-ups and free instant card top-ups. You’ll also get a second account (either UK account or Euro IBAN, depending on your first account) and card at zero extra cost.

Make savings with every transaction

We can confidently recommend Monese Premium as the best personal finance solution for those who travel frequently - whether it’s for business or pleasure. If you’re travelling for 3 months around the globe, or spending two weeks on holiday with the family, there’s no reason to worry about restrictions on withdrawals or charges on exchange rates. Everything is included in the cost - making for a money management experience that is completely unlimited.

Compared to our own Starter plan you can expect to make considerable savings on cash top-ups (£10 on a £500 Post Office top-up). You can also expect to rack up significant savings if you’re making regular international money transfers on a frequent basis - these could be potentially huge savings when compared to many high street banks.

No strings, no hidden fees

Monese Premium comes with no strings attached - if you don’t use it for an entire month (and don’t have any money in it), you won’t even be charged the monthly fee and there are no penalties. And you can always downgrade your plan whenever you like, without having to commit for a minimum term.

In the Monese Premium plan, we believe we’re offering something truly unparalleled, that champions our core ideals and our dedication to providing the very best service at the lowest possible prices. Whatever pricing plan you’re on, we’ll always present our costs of service in way that is completely transparent and ethical - and this latest addition is no exception.

To compare our all of our plans, you can have a look at our pricing page here.

We’ve launched XYB!
Company

We’ve launched XYB!

We’re super excited to announce the launch of XYB, our end-to-end ‘coreless’ banking platform provider that we believe could shake up the banking industry.

XYB helps banks and other non-banking financial institutions to make new financial services solutions accessible in record time. It breaks down the barriers of traditional core banking systems, meaning that businesses can provide the financial products and services they need, when and where they need them.

What’s coreless banking?

XYB is revolutionising banking technology. How you ask?

We’ve removed the dependency on traditional technology and old legacy processes. Instead we leverage highly configurable and scalable microservices architecture, and provide a turnkey solution with a pre-integrated partner ecosystem.

XYB is coreless banking at its finest, running independently without a centralised core system. This means that businesses can pick and choose the services and components we offer to build the solutions they need.

How we got here

At Monese, we’re proud to service millions of customers across Europe and the UK.

With backing from investors like PayPal Ventures, HSBC, Kinnevik, Investec, Augmentum and more, we’ve used our modern retail banking experience and the early success of our modular BaaS technology platform to create XYB, which promises to enable the new generation of financial services to all.

Investec was our very first customer to leverage XYB's cutting-edge coreless banking platform – and in under twelve months, we helped them to develop a new current account offering for their business clients.

This opening success was the perfect way to demonstrate the swift and efficient strength of XYB, and we couldn’t be more excited to see what happens next.

Our founder & CEO Norris Koppel said:

“XYB is testament to our commitment to breaking down the barriers in banking using best-in-class technology. XYB enables banks and non-banks to launch modern money services quickly and cost efficiently, helping millions more people access financial services across the world and empower businesses to grow.”

Industry feedback

We’re thrilled that Chris Skinner, an independent commentator on financial markets and fintech believes in XYB’s vision to break down banking barriers.

Chris said:

“For almost fifteen years we have been talking about the development of Banking-as-a-Service, the Platform Economy and Ecosystems. The concepts are robust in financial services, but the challenge is how to curate this system. With thousands of companies creating financial innovation, how can you leverage and utilise them?

What Monese with XYB has achieved is the curation of that system as a pre-emptive offer to turbo-charge banks into this environment. It’s very innovative and admirable, and fits into my views of the curated economy, where firms work together to improve the processes and deliver the best customer experience.”

Onwards and upwards

With his experience spearheading Monese's BaaS platform business, Atul Choudrie’s appointment as CEO at XYB is a natural fit for our vision.

Atul said:

"I am thrilled to be working with Norris to introduce XYB coreless banking ecosystem to the market, a true game-changer in the industry. With comprehensive managed services and a focus on collaboration, XYB promotes innovation, agility, and exceptional customer experiences, shaping the future of banking for all players, traditional and non-traditional alike."

Available initially in the United Kingdom and Europe, XYB is also set to launch in the North American and Asia Pacific markets. Watch this space!

Find out more at xyb.co