Marriott disclosed on Friday that it had left exposed 5.25 million unencrypted passport records along with 20.3 million encrypted passport credentials in a breach of its Starwood reservations database first disclosed a month ago.The background: The breach and unauthorized access to Starwood’s reservation network ran from 2014 through November, 2018. On September 8, 2018, Marriott received an alert from an internal security tool regarding an attempt to access the Starwood guest reservation database in the United States. Two months later, Marriott said up to 500 million guests could be involved in the break-in.The hotel giant has now revised downward to 383 million customer records it believes have been affected by the cyber theft. And, it suggested that figure could drop even lower as duplicate entries are identified. “The company has concluded with a fair degree of certainty that information for fewer than 383 million unique guests was involved, although the company is not able to quantify that lower number because of the nature of the data in the database,” Marriott said in a posted statement.There is some additional information on the theft of some nine million encrypted bank cards, including more than 350,000 still active as of last September. The company said there is no evidence that the hackers were able to decode payment card numbers. It conceded that it’s a bit less certain about the unencrypted bank cards stolen in the hack. Marriott said it is “undertaking additional analysis” to see if payment card data was "inadvertently entered into other fields and was therefore not encrypted.” It’s possible, Marriott said, that roughly 2,000 of 15- and 16-digit numbers “in other fields in the data involved“ could be unencrypted payment card numbers. Right now, Marriott doesn’t know nor does it have a concrete process in place to help those customers that may be affected.