Cyber data breach: Marriott vs Quora

There are lessons to be learned here.... have a read and tell me what you think:
Marriott:
https://www.sans.org/security-awareness-training/blog/what-communicate-about-marriott-hack
Quora:
https://mobile.abc.net.au/news/2018-12-04/quora-hack-sees-100-million-users-data-stolen/10582126
Marriott:
https://www.sans.org/security-awareness-training/blog/what-communicate-about-marriott-hack
Quora:
https://mobile.abc.net.au/news/2018-12-04/quora-hack-sees-100-million-users-data-stolen/10582126
Certs: GSTRT, GPEN, GCFA, CISM, CRISC, RHCE
Check out my YouTube channel: https://youtu.be/ug_ruisDUXc
Comments
Have you been following the comments on Krebs? Really interesting stuff: https://krebsonsecurity.com/2018/12/what-the-marriott-breach-says-about-security/
Who we are | What we do
Security Engineer/Analyst/Geek, Red & Blue Teams
OSCP, GCFA, GWAPT, CISSP, OSWP, AWS SA-A, AWS Security, Sec+, Linux+, CCNA Cyber Ops, CCSK
2021 goals: maybe AWAE or SLAE, bunch o' courses and red team labs?
Well it's been alarming. Companies here are all recruiting and trying to build "Cyber" or "Security" Capabilities...everyone wants to be ready to disclose for any breaches. Even international companies with Australian presence have to disclose in case of any breach. PageUp coped it this year, everyone company that used PageUp at some people had to send an email notice, it was chaotic.
Security Engineer/Analyst/Geek, Red & Blue Teams
OSCP, GCFA, GWAPT, CISSP, OSWP, AWS SA-A, AWS Security, Sec+, Linux+, CCNA Cyber Ops, CCSK
2021 goals: maybe AWAE or SLAE, bunch o' courses and red team labs?
Security Engineer/Analyst/Geek, Red & Blue Teams
OSCP, GCFA, GWAPT, CISSP, OSWP, AWS SA-A, AWS Security, Sec+, Linux+, CCNA Cyber Ops, CCSK
2021 goals: maybe AWAE or SLAE, bunch o' courses and red team labs?
Rant over.
yeah, thats what the dark web chatter from the time period reflected, openly traded and commented, my guess is some very advanced actor used all this to burrow their selves deep into the starwood network and began slowly siphoning data off... there are a couple of OSINT sources pointing fingers at China... think Dark Hotel ops from a couple of years ago