The encyclopedia · Software & IT · Operational decision · 2018
Marriott's Starwood breach exposed 500M guests' data — and it went undetected for 4 years
In 2018, Marriott disclosed that hackers had accessed 500M Starwood guest records since 2014. The breach went undetected for 4 years through the merger.
Marriott International · Starwood Hotels · 2018-11
What happened
In November 2018, Marriott International disclosed that hackers had accessed the guest reservation database of its Starwood Hotels division, compromising approximately 500 million guest records. The breach had begun in 2014 — before Marriott acquired Starwood in 2016 — and went undetected for approximately four years.
The stolen data included names, addresses, phone numbers, email addresses, passport numbers, and in some cases, encrypted credit card numbers and travel itineraries. The breach was one of the largest in hospitality history and raised concerns about state-sponsored espionage, as the data could be used for intelligence purposes.
Marriott was fined £99 million by the UK's Information Commissioner's Office (later reduced to £18.4 million) for failing to protect customer data. The case illustrated how an acquisition can inherit a security breach along with the assets, and how a breach that goes undetected for years can span multiple ownerships without either company discovering it.
Why it happened
- Hackers accessed Starwood's guest database in 2014, before the Marriott acquisition.
- The breach went undetected for 4 years, spanning the Starwood-Marriott merger.
- 500M guest records were compromised, including passport numbers and travel data.
- Marriott was fined £99M (later reduced) by the UK ICO.
The lesson
An acquisition inherits the target's security posture along with its assets. Marriott bought Starwood's hotels and its undetected breach. Due diligence that skips the network logs is incomplete.
Aftermath
Marriott was fined by the UK ICO and overhauled its security practices. The Starwood reservation system was decommissioned. The case prompted the hospitality industry to strengthen data security and influenced GDPR enforcement in the UK.
Sources
spotted an error? The club wants to know.
More like this
Arrival raised $13B on a promise of 'micro-factories' — and never built a van
Dyson built 5,127 prototypes that nobody wanted — then his vacuum sold itself
A teenager trying to cure malaria accidentally created the first synthetic dye
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.