Home Blog Page 227

Remote Workforce: Five Best Practices for Organisations to Ensure Cybersecurity

75% Of Security Pros Say Remote Work Led to Changes in Financial Services Cyber Programs: Survey

In the last couple of weeks, the world has changed in unprecedented ways. Owing to the Coronavirus pandemic, companies across the country have resorted to remote working while advocating work from home policies to ensure business continuity. In the process, organizations have been rushing to embrace technology to allow collaboration and ensure productivity with various tools for video conferencing, chat applications, tech support and so on. Clearly, we are in living in a hyper-connected world.

By Mary Jo Schrade, Assistant General Counsel, Regional Lead, Microsoft Digital Crimes Unit Asia

The main focus of employees now is managing their tasks and responsibilities – both at home and at their remote workplace; and while technology has enabled much of it, the current scenario may lead to a wavering attention towards ensuring cybersecurity, greatly affecting each organization’s security profile. In this scenario, CISOs and admins must urgently look at new scenarios and models to address new threat vectors, as their places of work transform into distributed organizations overnight.

Here are five best practices for organizations and employees to follow:

  • Team up and manage logins: Employees are chatting and sharing more than usual during this time, even if there isn’t an official tool provided by IT. That’s why we recommend all employers take advantage of the six months of free premium Microsoft Teams which now has no limit on how many users can join or schedule video calls using the “freemium” version. That way, employees know which channels to use, and CISOs can better manage them securely.
  • Sensitize employees about Phishing attempts: Remote workers have access to propriety data and information and your network. Warn employees to expect more phishing attempts, including targeted spear phishing aimed at high profile credentials. Be clear on what official communications about business continuity and health and safety should look like, and from where they should originate. Have employees watch out for urgent requests that violate company policy, use emotive language and have details that are slightly wrong—and provide guidance on where to report those suspicious messages.
  • Establish a clear communications policy: Establishing a clear communications policy helps employees recognize official messages. For example, video is harder to spoof than email: using an official channel like Microsoft Stream can ensure employees are able to distinguish legitimate communications from phishing, while helping people to feel more connected; and on-demand streaming also helps employees juggling personal responsibilities, like school closures or travel schedule changes.
  • Warn about suspicious links: 91% of cyberattacks start with an email, which either leads to malicious links directly or which contains dangerous attachments. Warn employees not to click on links if they suspect an email to be a scam. One method of testing the legitimacy of a link is to rest your mouse—but not click—over the link to see if the address matches what was typed in the message. Note that the string of IP address numbers looks nothing like the company’s web address.
  • Suspicious attachments: Likewise, do not open attachments in emails that are from strangers, or an email from someone you do know but with an attachment you weren’t expecting, it may be a phishing attempt, so we recommend you do not open any attachments until you have verified their authenticity. Attackers use multiple techniques to try and trick recipients into trusting that an attached file is legitimate.

It is estimated that since the pandemic began, hackers have ramped up phishing and ransomware attacks fivefold. It is more crucial now, than ever for every employee of an organization to uphold the best practices of cybersecurity.

About the Author

Mary Jo Schrade is responsible for supervising the initiatives, programs and strategies related to preventing and disrupting organized cybercrime, piracy and online tech support scams through public-private partnerships, coordinating enforcement, and engaging in public speaking relating to cyber security and Microsoft’s digital trust commitments to our customers.

Disclaimer: CISO MAG does not endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. Views expressed in this article are personal.

 

45% of Employees Don’t Know How to Respond to Ransomware Attacks: Research

Hive Ransomware

A new research from Kaspersky revealed employees’ perceptions and readiness towards ransomware attacks. According to the research, employees across various business organizations of all sizes lack basic knowledge on cybersecurity and cyberattacks. It revealed that 45% of respondents in North America, including the U.S. and Canada, stated that they don’t know how to respond to a ransomware attack.

The research highlighted that 37% of the respondents were unable to define the term ransom and ransomware. For respondents who have previously experienced a ransomware attack, two in five respondents (40%) said they don’t know the necessary steps that need to be taken in response to a ransomware attack. While 30% of them said that disconnecting a computer from the internet would be the first step to stop the attack. Additionally, 68% of the surveyed employees feel that IT security teams are responsible to take care of cyberattacks. Kaspersky also mentioned that around 900,000 to almost 1.2 million of all users were targeted by ransomware attacks every six months, and the amount of ransom cost up to US$1,032,460 on average.

Rising Ransomware Threats in the U.S.

A similar research from Trend Micro found a 10% increase in ransomware detections, despite a 57% decrease in the number of new ransomware families. In its Annual Threat Report 2019, the company stated that the health care sector remained the most targeted industry, with more than 700 providers affected in 2019. According to the report, nearly 110 state and municipal governments and agencies in the U.S. fell victim to ransomware last year. Trend Micro disclosed 171% more high severity vulnerabilities than in 2018. In order to defend against threat landscape, the firm also suggested enterprises to adopt connected threat defense across gateways, networks, servers, and endpoints.

New Zoom Bug Lets Hackers Compromise Windows Credentials

cyberthreats, bug

Security researchers claimed that online video meeting platform Zoom is vulnerable to remote attacks. According to cybersecurity expert Mitch@_g0dmode, Zoom’s video conferencing software for Windows is vulnerable to “UNC path injection” flaw that could let hackers steal Windows passwords and execute arbitrary commands on their devices, The Hacker News reported.

The researcher stated that these kinds of attacks are possible because Zoom for Windows software supports remote UNC paths that convert insecure URIs into hyperlinks when received via chat messages. Zoom is a cloud-based enterprise communication platform with over 74,000 customers and 13 million active users. It offers chat, audio, video conferencing, and options to host webinars and virtual meetings online.

How Does the Bug Work?

The existence of the vulnerability is also confirmed by security researchers Matthew Hickey and Mohamed Baset, who stated that attackers exploit the process where Windows inevitably exposes a user’s login username and NTLM password hashes to a remote SMB server while downloading a file hosted on it. In order to steal passwords, the attacker needs to send a crafted URL (i.e., \\x.x.x.x\abc_file) to a victim via a chat interface. Once the user clicks the URL, it eventually allows the attacker-controlled SMB share to capture the verification data from Windows, without the user knowledge.

 Zoom Fixes the Bug

Soon after the vulnerability was identified, the company fixed the issue by releasing a patch. The CEO of Zoom, Eric Yuan, addressed the security issues and stated that a patch has been released to fix the UNC vulnerability. The fix will be pushed out automatically to all the users.

In a blog post, Yuan said, “We recognize that we have fallen short of the community’s – and our own – privacy and security expectations. For that, I am deeply sorry, and I want to share what we are doing about it. For the past several weeks, supporting this influx of users has been a tremendous undertaking and our sole focus. We have strived to provide you with uninterrupted service and the same user-friendly experience that has made Zoom the video-conferencing platform of choice for enterprises around the world, while also ensuring platform safety, privacy, and security.”

FBI Slams Zoom

Recently, the FBI slammed Zoom for not maintaining proper privacy and security measures for its users. The authorities also warned that the video meeting app is prone to hacking, as it has certain unpatched bugs.

Cybercriminals Target Zoom Domains to Distribute Malware

With majority of the employees working remotely, online communication platforms like Zoom saw a sudden increase in their popularity.  According to a report from Check Point, hackers are taking advantage of the rise in Zoom usage by registering fake and malicious Zoom domains. The report stated that around 1,700 new Zoom domains have been registered since the pandemic, with 25% of the domains registered in the past seven days alone.

Axonius Raises US$58 Million to Accelerate its Security Management Tool

Axonius Raises US$58 Million to Accelerate its Security Management Tool

Axonius, a developer of end-to-end device management platform, announced that it has raised US$58 million in a Series C funding round led by Lightspeed Venture Partners along with participation from existing investors OpenView, Bessemer Venture Partners, YL Ventures, Vertex, and WTI. The Israel-based startup stated that it will utilize the new funds to accelerate its customer growth, further develop product innovations, and expand the offerings of its flagship product—Cybersecurity Asset Management Platform.

Axonius provides cybersecurity asset management services to public and private enterprises with its cybersecurity asset management platform that integrates information from connected devices to manage and secure them constantly. Its asset management platform creates a single point of view into connected devices, including desktops, laptops, servers, cloud instances, mobile devices, and other IoT on a company’s network and automatically detects whether those assets fit within the stipulated security policies or not.

Commenting on the new investment, Dean Sysman, CEO and Co-Founder at Axonius, said, “Our goal is to go public as an independent cybersecurity asset management platform. But I hope that this new funding round with the most proven investors in our industry serves to send a bold message to our customers and the market. Axonius has enjoyed exponential growth by solving a real problem, taking away manual work, and letting security and IT teams focus on what’s important.”

In February 2019, Axonius raised US$13 million in its Series A funding round led by Bessemer Venture Partners along with the participation from existing investors YL Ventures, Vertex, WTI, and Emerge.In August 2019, the company raised US$20 million in its Series B funding round led by OpenView.

Cybersecurity Startup Exits in 2019

According to the IVC Research Center report, Israel has 436 cybersecurity companies operating across various verticals of development. The cybersecurity exit totaled to US$11.3 billion within a timeframe of 2013 to 2019. The exit costing increased exponentially and so has the funding for Israeli cybersecurity companies during the same time period. Israeli cybersecurity startups have managed to attract funding of US$6.32 billion from investors across 594 deals.

Israel’s Cyber Startup Hub

With rising global competition in the cybersecurity market, Israel faced a decline in the cyber startups ecosystem, according to Zohar Rozenberg, Vice President of Cyber Investments at Elron and RDC. The country always valued bold innovation and planning, however investment in cybersecurity was down.

Israel saw only 40 new cybersecurity startups in 2019, a 33% decline compared to 60 new startups in 2016. Investors are preferring rapid revenues over innovation, whereas, global technology corporates are competing over talent with entrepreneurial capacities. As cyber challenges grow in Fintech, Insurtech, automotive, and manufacturing industries, Israel needs investment and critical mass support to boost its talent and infrastructure.

Hackers Attack Around 300,000 Devices in South Africa Amid COVID-19 Crisis

Cloud of Logs dark web market

The surge in remote work increased cybersecurity risks adding to the COVID-19 pandemic. Several industry experts stated that organizations in financial, health care, federal, and state agencies that deal with sensitive data will have a huge impact due to remote working conditions.

Based on a research from Kaspersky, businesses in South Africa suffered several network attacks between March 15 to March 21, 2020. It revealed that cybercriminals attacked up to 310,000 devices in one week. With millions of people in the country accessing corporate networks remotely, hackers have increased attacks on IT networks, MyBroadband reported.

The research also highlighted that hackers targeted corporate network systems to gain control over them and compromise sensitive information. Most of the hacking attempts in South Africa involved brute force attacks, which are intended to steal passwords and other credentials.

Commenting about the current scenario in South Africa, Maher Yamout, Senior Security Researcher for the Global Research and Analysis Team at Kaspersky, said, “The region is seeing an increase in attempts to break into the organizations’ systems to establish control over them, sabotage their work, or access sensitive information,”

“Remote working provides cybercriminals a prime opportunity to target devices, especially those that don’t necessarily have adequate IT security measures in place. Such a spike recorded, although temporary, leads us to believe that cybercriminals have keenly been focused on the region given the current circumstances,” Yamout added.

Kaspersky also recommended a few tips to employees working remotely during the lockdown. These include:

  • Make use of a VPN to connect securely to the corporate network
  • Use multi-factor authentication wherever possible
  • Ensure all corporate devices – including mobiles, laptops, and tablets are protected with adequate security software
  • Segregate your personal devices/life from corporate computers
  • Ensure the latest available updates are installed regularly
  • Only use corporate-approved teleconferencing software
  • Practice basic cybersecurity rules

Hacker Hijacks 30 YouTube Accounts to Broadcast Bill Gates-themed Bitcoin Ponzi Scheme

Hackers Selling Stolen YouTube Credentials on Dark Web: Report

Since the inception of Bitcoin in 2009, there is a significant evolution of blockchain technology. On the flip side, the unique features of bitcoin and other cryptocurrency attracted the eyeballs of several cybercriminals. Over the years, hackers have masterminded numerous techniques to launch cryptocurrency hacks and scams.

Recently, a hacker impersonated Microsoft’s former CEO Bill Gates to publicize a Bitcoin Ponzi scheme. Almost 30 YouTube accounts were hijacked to broadcast a video of Bill Gates (using his fake image) promoting their cryptocurrency Ponzi scheme.  The hacker asked viewers to invest in their Bitcoin scheme by paying an entry fee of 0.1 BTC (approximately US$650), Naked security reported.

The compromised YouTube channels carried the thumbnail photo of Bill Gates with the topic “Microsoft Bitcoin Investment News.” The hacker also changed the names of the channels to seem like they were authentic Microsoft brands such as Microsoft US, Microsoft Europe, and Microsoft News. It’s believed that the hacker had taken Bill Gates’ quotes from his previous speeches and layered them with details of the Ponzi scheme.

However, YouTube took down all the hijacked channels immediately after discovering the incident. Microsoft also clarified that none of its verified accounts were hacked and there is no sign of data breach.

Hackers Target Popularity of Famous Personalities

This is not the first time that hackers used the names of famous personalities for their advantage. Earlier, Kaspersky researchers found a staggering 39% rise in attacks which includes attempts to download or run malicious files disguised as Grammy Award nominees’ work in 2019, compared to 2018.

The researchers said that cybercriminals targeted the popularity of pop stars such as Ariana Grande, Taylor Swift, and Post Malone, with over half (55%) of detected malicious files named after them. The regions most affected with these malware attacks are the UAE and Nigeria. The number of users attacked by malware disguised as Billie Eilish songs in UAE accounted for 31,782, whereas in Nigeria this number totaled 9,722. Overall, the UAE saw 61 such malicious files distributed in the region in 2019, with a total of 100,961 cyberattacks. Similarly, Nigeria saw 55 such malicious files distributed in 2019, with 94,630 cyberattacks.

Tech Against Corona: A Cybersecurity Campaign to Fight COVID-19-related Cybercrimes in the Netherlands

Tech Against Corona: A Cybersecurity Campaign to Fight COVID-19-related Cybercrimes in the Netherlands

A group of organizations in the Netherlands have launched the “Tech against Corona” campaign to help the Dutch government with their technology and security skills, and mitigate COVID-19-related cybercrimes. The companies participating in the campaign will offer their technology, algorithms, and security services to the government entities, aid workers, health care providers and hospitals free of charge, Public Matters reported.

As part of the operation, cybersecurity firm Cybersprint discovered fake websites and COVID-19-related malware attacks against various hospitals in the country. The company also offered its security solutions to these hospitals for further protection.

Blockchain company Tymlez stated that it is going to provide its distributed ledger technology (DLT) services to the government and health care organizations. The company claimed that its DLT-enabled platform will bring transparency to the medical supply chain by preventing harmful and manipulative activities including price gouging, during the ongoing medical crisis.  In addition, security solutions provider Compumatica is offering its services to secure the internet connections of remote workers in critical professions.  Similarly, more than 10 Netherlands-based companies are offering their services in order to help the government in securing the country from opportunistic cybercriminals.

 Credential Phishing Attacks on Netherlands-based Firms

As employees are working remotely during this crisis, there is a rise in social engineering, malware, and phishing attacks targeted to trick people into opening Coronavirus-related malicious links or attachments.

Several credential phishing attacks were targeted on Netherlands-based manufacturing, technology, and industrial firms. Hackers are sending fraudulent messages claiming that a major bank from the country is providing “antibacterial debit cards” and asking recipients to apply for it. In this fake message/e-mail, the recipients are asked to click on a link to apply for the card, but it’s a trap and the sender is trying to capture the login credentials of Rabobank customers. Even Rabobank warned its customers to be vigilant about fake announcements. The bank clarified that they are not offering any cards at present.

India to Get a New Cybersecurity Policy

Acronis Cyber Readiness Report, cyberattacks in India, cybercrime in India, India’s Private Sector

Indian telecom service providers offer the lowest data rates in the world. India is also the most populous country, with 1.3 billion people. More than half its population comprise youth below the age of 25 years. And smartphones are the primary source of Internet access for most Indians. With the availability of affordable data packs and falling smartphone prices, Indians are consuming more services (and data) on the Internet, through mobile apps, and of course, by watching a lot of videos! Digital payments and mobile wallets took off after the Government of India announced demonetization in 2016. All this makes Indian consumers prime targets for hackers who are out to steal user credentials (like credit card numbers and authentication details) and money from mobile wallets.

By Brian Pereira, Principal Editor, CISO MAG

A report from Symantec Corp. (now part of Broadcom) last year revealed that India is the second most cyberattacked country in the world, after the U.S. and China. This was widely reported in the media. Indian law, notably the Indian IT Act 2000, does not fully protect its citizens from new threat vectors like phishing, SIM jacking, ransomware, mobile payments fraud, bank fraud, malware attacks, social engineering, and DDoS attacks—all increasingly common these days. But the Indian government is expected to release a new cybersecurity policy this year. India’s Personal Data Protection Bill is also under review and is expected to be passed this year.

Speaking at the Cybersecurity India Summit 2020 in New Delhi last month, Lt. Gen. (Dr) Rajesh Pant, National Cyber Security Coordinator, Prime Minister’s Office, Government of India, said the new policy would be introduced in two to three months, that would make it May or June 2020. Pant said the new cybersecurity policy would address all the issues related to Cyber ecosystem like standardization, testing, auditing and capacity building. This was reported by The Economic Times.

In a presentation made previously, Dr. VK Saraswat, Member, NITI Aayog, said cybersecurity is crucial to all industries in India today–to protect critical infrastructure from attacks, damage, misuse, and economic espionage. He said the top five causes of “cyber disruptions” are phishing and social engineering, malware, spear phishing, denial of service, ransomware, and out of date software.

Most Indian organizations have already been attacked by hackers, though only few incidents are reported in the media. CERT-In (the Indian Chapter of the global Computer Emergency Response Team), has the authority to penalize Indian organizations that do not report breaches.

While corporate India and Indian citizens keenly await the new cybersecurity policy, we can only hope that it will provide robust protection for businesses and consumers—and give them legal teeth to fight attackers.

Five Reasons Why Organizations Fail in Their GDPR and CCPA Compliance

GDPR

Despite GDPR being in place for over a year, and CCPA being rolled out in January this year, some organizations have not been able to change their data handling practices accordingly. Since the enforcement of GDPR, there have been over 160,000 personal data breaches within the European Economic Area, and failures of data governance trigger the most fines and penalties. Based on findings in the recent 2020 Netwrix Data Risk & Security Report, there are five worrisome compliance practice gaps that can incur high costs.

By Ilia Sotnikov, VP of Product Management at Netwrix

Problem #1: Organizations that are subject to the GDPR collect more customer data than the law permits. 

Organizations are definitely not going for minimalism to honor GDPR’s data minimization mandate. The GDPR’s Article 25 requires the controller to ensure that only personal data, which is necessary for each specific processing purpose, is collected and processed. If an organization stores more personal data, it’s misleading customers.

However, the majority (61%) of the organizations surveyed say they store more personally identifiable information (PII) than they should. So they can share the fate of Deutsche Wohnen having to pay €14,5 million fine (approximately US$15.9 million) for issues around the storage and deletion of tenants’ personal data.

Problem #2: Organizations subject to the GDPR and CCPA don’t categorize personal data they gather.

41% of respondents subject to the GDPR and 42% subject to the CCPA don’t discover and classify data at the point of creation and aren’t able to quickly search through the records, or are unaware if that capability exists in their organization. Data inventory and records management is not an official requirement, but it is essential to comply with the regulations’ key requirements. For instance, there is no way to apply appropriate security controls to regulated data if you don’t actually know where it is located. Also, without proper search capabilities, satisfying data subject access requests while not putting business on hold is nearly impossible.

Problem #3: CISOs and Compliance Officers are not sure if regulated data is stored in a secure location.

66% of CISOs and Compliance Officers in the organizations surveyed doubt that regulated data is stored in a secure location. Nearly half of undecided CISOs (45%) work for the organizations subject to GDPR. Though it is business units that own non-compliance risks, IT security pros play the quarterback role in managing the technical part of compliance. So CISOs are expected to be aware if regulated data is stored securely and not to leave it to luck.

Problem #4: GDPR and CCPA-compliant organizations don’t track how regulated data is shared.

Organizations that fall under privacy legislations should maintain a trail of the footprint of personal data they hold on consumers and employees. However, 33% of organizations subject to the GDPR and 25% subject to the CCPA do not track data sharing at all.

Problem #5: GDPR-compliant organizations don’t have a data retention program in place.

The GDPR requires organizations to discard regulated data no longer needed: The Recital 39 states that time limit should be established by the controller for erasure or for a periodic review to ensure that the period for storing the PII is limited to a strict minimum. Yet, according to our data, 52% of organizations that are subject to the GDPR still haven’t established data retention program. In fact, excessive storage has already been one of the reasons to fine the real estate company SERGIC in France. Apart from lacking basic security measures, the company stored the documentation provided by candidates for longer than necessary. This resulted in a €400,000 fine.

Major areas for growth 

These stats demonstrate that there’s a lot to be done to reach compliance maturity in the organizations.

First, privacy compliance requires business commitment–it is when IT and business should answer the key questions together, such as “What kind of data does our organization hold and why?” “Do we collect data for legitimate purposes?” “How does data travel across the company?” Only together, they can build a healthy compliance strategy, since privacy compliance is not a standalone IT project.

Second, there are certain technical measures that can help organizations grow their ‘compliance muscle’ and protect privacy by design, such as creating data inventory (as IT may not know in detail the data but they should know which databases and folders are critical), regularly auditing activity around data and configuring smart alerting if data is mishandled.

Also, communication should not be limited to the specific business’ stakeholders. There are thousands of other organizations that fight in the compliance battle, so it is important for the organizations to gain and share knowledge in professional networks, conferences and meetups.

What to expect

Privacy compliance brings a lot of confusion, but with time we will see more guidance, instruments and frameworks that will help organizations achieve privacy compliance in a less painful way. Best practices are yet to be standardized, so, as of now, security and compliance professionals should accumulate knowledge together.

Finally, we should keep in mind that there are more privacy regulations to come. To be ready for tomorrow, organizations should establish mature data governance processes today. Thus, it is crucial for any organization that collects PII to understand the data flows in its environment and track what happens to regulated data at each stage of data lifecycle: from initial collection to disposal.

About the Author

Ilia Sotnikov is responsible for Netwrix product vision and strategy. He has over 15 years of experience in IT management software market. Prior to joining Netwrix in 2013, he was managing SharePoint solutions at Quest Software (later acquired by Dell).

Disclaimer: CISO MAG does not endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. Views expressed in this article are personal.

It Happens Again! Marriott’s Data Breach Exposes Records of 5.2 Million Guests

Marriott International’s Data Breach Exposes Records of 5.2 Million Guests

Hospitality group Marriott International announced that it has been hit by a data breach that exposed the personal information of around 5.2 million guests. In an official release, the company stated that the breach began in mid-January 2020 and was discovered at the end of February 2020. The incident exposed contact details including names, addresses, birth dates, gender, email addresses, employer name, room stay preferences, and loyalty account numbers. However, Marriott clarified that passport information, payment details, and passwords were not exposed in the breach.

It’s believed that the exposed data has been accessed by an unknown third party using the login credentials of two employees at a group hotel, which is operated and franchised under Marriott’s brand. Marriott notified the incident to the relevant authorities for further investigation and informed those who were affected in the breach. Marriott also set up a website to help the impacted guests in the incident.

“Hotels operated and franchised under Marriott’s brands use an application to help provide services to guests at hotels. At the end of February 2020, the company identified that an unexpected amount of guest information may have been accessed using the login credentials of two employees at a franchise property,” the company said in a statement. “Although our investigation is ongoing, we currently have no reason to believe that the information involved included Marriott Bonvoy account passwords or PINs, payment card information, passport information, national IDs, or driver’s license numbers.”

Not the First Time

This is Marriott’s second breach incident after a massive data leak was announced in 2018, which saw around 500 million guests’ data exposed over the course of several years. Hackers extracted people’s personal data like passwords, loyalty program payment, reservation information, as well as encrypted credit card data of 100 million customers. The first breach originated in 2014 at Starwood, which was acquired by Marriott International in 2016, and was uncovered after four years in September 2018, when an internal security tool alerted the staff about the unauthorized data access. Consequently, the company faced a class-action suit, which led to a decline in its shares by 5.6%.

Big Blow for Marriott

In July 2019, the U.K.’s Information Commissioner’s Office (ICO) imposed £99.2 million (US$123.7 million) fine on Marriott International, for the data breach. The ICO stated that Marriott failed to protect its customers’ information, violating the EU’s GDPR regulations.