Back to the archive

The encyclopedia · Software & IT · Operational decision · 2018

Marriott's Starwood breach exposed 500M guests' data — and it went undetected for 4 years

In 2018, Marriott disclosed that hackers had accessed 500M Starwood guest records since 2014. The breach went undetected for 4 years through the merger.

Marriott International · Starwood Hotels · 2018-11

What happened

In November 2018, Marriott International disclosed that hackers had accessed the guest reservation database of its Starwood Hotels division, compromising approximately 500 million guest records. The breach had begun in 2014 — before Marriott acquired Starwood in 2016 — and went undetected for approximately four years.

The stolen data included names, addresses, phone numbers, email addresses, passport numbers, and in some cases, encrypted credit card numbers and travel itineraries. The breach was one of the largest in hospitality history and raised concerns about state-sponsored espionage, as the data could be used for intelligence purposes.

Marriott was fined £99 million by the UK's Information Commissioner's Office (later reduced to £18.4 million) for failing to protect customer data. The case illustrated how an acquisition can inherit a security breach along with the assets, and how a breach that goes undetected for years can span multiple ownerships without either company discovering it.

Why it happened

  • Hackers accessed Starwood's guest database in 2014, before the Marriott acquisition.
  • The breach went undetected for 4 years, spanning the Starwood-Marriott merger.
  • 500M guest records were compromised, including passport numbers and travel data.
  • Marriott was fined £99M (later reduced) by the UK ICO.
What it cost500M records; £99M fine; 4 years undetectedcostly

The lesson

An acquisition inherits the target's security posture along with its assets. Marriott bought Starwood's hotels and its undetected breach. Due diligence that skips the network logs is incomplete.

Aftermath

Marriott was fined by the UK ICO and overhauled its security practices. The Starwood reservation system was decommissioned. The case prompted the hospitality industry to strengthen data security and influenced GDPR enforcement in the UK.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →