Breach report
Travel & HospitalityMarriott International (Starwood)
Marriott: Data on 500 Million Guests Stolen in 4-Year Breach
Intruders lurked inside Starwood's guest reservation database from 2014 until 2018, exposing records on up to 383 million guests, including millions of passport numbers, and leaving Marriott to answer for a breach it inherited through acquisition.
Reported by Krebs on Security
Records exposed
383M
Up to 383 million guest records (initially reported as 500 million)
Scale vs. largest on file
- When
- 2014–2018 (disclosed 2018)
- How they got in
- Long-term network intrusion into Starwood reservation system
- Sector
- Travel & Hospitality
On November 30, 2018, Marriott International announced that its Starwood guest reservation database had been breached, with information on up to 500 million guests potentially exposed. The hotel giant, which had acquired Starwood Hotels & Resorts in 2016, said an internal security tool flagged a suspicious attempt to access the database on September 8, 2018, and that investigators then discovered unauthorized access dating back to 2014, well before the acquisition closed.
For about 327 million guests, the exposed data included some combination of name, mailing address, phone number, email address, passport number, Starwood Preferred Guest account information, date of birth, gender, arrival and departure details and reservation dates. Some records also contained payment card numbers that were encrypted, though Marriott said it could not rule out that the decryption keys had been taken. In January 2019, after removing duplicates, the company revised its estimate to about 383 million guest records, including roughly 5.25 million unencrypted passport numbers.
Marriott did not publicly attribute the attack, but several news organizations, citing people familiar with the investigation, reported that it was linked to a Chinese state-backed intelligence-gathering effort. The theft of passport and travel data fit a broader pattern of espionage campaigns targeting information about government employees and frequent travelers. No large-scale sale of the data on criminal markets was widely documented, which was consistent with that explanation.
Regulators pursued the company on both sides of the Atlantic. In 2020 the U.K. Information Commissioner's Office fined Marriott £18.4 million under GDPR, down from a proposed £99 million, noting the company failed to carry out adequate due diligence on Starwood's systems. In 2024 Marriott agreed to pay $52 million to settle claims from 50 U.S. states and the District of Columbia and entered a settlement with the Federal Trade Commission requiring a comprehensive information security program. Consumer class actions continued for years, and the company's shares fell on the day of the announcement.
The Starwood breach became a defining case for cybersecurity due diligence in mergers and acquisitions: Marriott bought a network that had already been compromised and did not detect the intruders for two more years. It also underscored why hotels, which collect passport and travel data, are attractive targets for state-backed spies as well as criminals. Guests were advised to watch for phishing and, where passport numbers were exposed, to consider the risks of identity misuse.