By Joe Sutton and Holly Yan, CNN
— White Lodging — a company that maintains Hilton, Marriott, Sheraton and Westin hotel franchises — has apparently suffered a data breach that exposed guests’ credit and debit card information in 2013, independent security researcher Brian Krebs
Banking industry sources noticed fraud among hundreds of cards that had been previously used at Marriott hotels, wrote Krebs, who first reported that Target had suffered a massive data breach around Black Friday last year.
“But those same sources said they were puzzled by the pattern of fraud, because it was seen only at specific Marriott hotels, including locations in Austin, Chicago, Denver, Los Angeles, Louisville and Tampa,” Krebs wrote.
“Turns out, the common thread among all of those Marriott locations is that they are managed” by White Lodging, he said.
White Lodging, which is based in Merrillville, Indiana, issued a statement Sunday night in response to the findings.
“An investigation is in progress, and we will provide meaningful information as soon as it becomes available,” White Lodging said in a statement.
Marriott said it will continue to monitor the situation.
“We are working closely with the franchise management company as they investigate the matter,” spokesman Jeff Flaherty said. “Because the suspected breach did not impact any systems that Marriott owns or controls, we do not have additional information to provide.”
White Lodging is just the latest American business to investigate a security breach.
The hacking of Target’s systems could be the largest breach in U.S. retail history. It affected up to 110 million customers, including 40 million credit and debit cards and up to 70 million customers’ personal information.
The retailer discovered the breach in mid-December, notified customers several days later, and launched an investigation with the help of a private security firm and law enforcement.
Since Target’s disclosure, high-end retailer Neiman Marcus announced over 1 million customer cards were compromised in a breach last summer.
And last month, crafts retailer Michaels said its systems may have been breached.
It isn’t immediately clear if these possible attacks are related. Security experts have warned it is likely other companies were targeted by the hackers who hit Target.
U.S. Attorney General Eric Holder spoke about a federal investigation at a Senate hearing last week.
“We are committed to working to find not only the perpetrators of these sorts of data breaches, but also any individuals and groups who exploit that data via credit card fraud,” Holder said.