← Case Files · The Breach Files

2018 · Hospitality

Marriott and Starwood, 2018: a breach that came with the acquisition

Case file · 4 min read · Published 14 September 2026

People affected
about 339 million guest records
When it happened
2014 – September 2018
Made public
30 November 2018
How they got in
Long-running compromise of the Starwood reservation system, present before the acquisition
Attributed to
Publicly linked by US officials to Chinese state actors; never charged
What it cost
£18.4 million fine from the UK Information Commissioner's Office

What was exposed: Names · Addresses · Phone numbers · Email addresses · Passport numbers (5.25 million unencrypted) · Arrival and departure dates · Reservation details · Some encrypted payment cards

Marriott announced in November 2018 that its Starwood guest reservation database had been compromised. The striking detail was not the number of records. It was the start date: 2014 — two years before Marriott bought Starwood, and four years before anyone noticed.

What happened

Starwood Hotels and Resorts operated brands including Sheraton, Westin, W and Le Méridien. Its central reservation database held guest records going back years. Attackers were inside that system from 2014.

Marriott completed its $13 billion acquisition of Starwood in September 2016, creating the largest hotel group in the world. It continued to run the inherited Starwood reservation platform alongside its own while migration work proceeded. In September 2018, an internal security tool flagged an attempt to access the Starwood database. The investigation found the long-running compromise.

The first public figure was "up to 500 million guest records". By January 2019 Marriott had revised it to roughly 339 million, of which about 5.25 million held unencrypted passport numbers, 20.3 million held encrypted ones, and some 8.6 million contained encrypted payment card details.

Why the passport numbers mattered most. Card numbers were encrypted, and cards expire. A passport number does not expire for a decade and cannot be casually reissued; in most countries replacing one costs the holder money and time. Five million of them, matched to names, addresses and travel dates, is a durable identity dataset and a precise record of international movement.

Why this reads as espionage rather than crime

Criminal groups monetise breaches: cards get sold, credentials get stuffed, identity kits get traded. Four years of hotel reservation data attached to passport numbers has an obvious market value — and none of it showed up on carding forums.

US officials publicly linked the intrusion to Chinese state actors, and the reasoning offered at the time turned on this absence. A dataset that records where specific named people slept, on which nights, in which cities, is a counterintelligence tool. Cross-referenced with the OPM clearance files and the Anthem membership records, both attributed to the same country, it starts to look less like three unrelated thefts and more like an assembly job: who people are, what could pressure them, and where they have been.

No charges have been brought, so the attribution remains an assessment by officials rather than a finding in court. It is worth stating that plainly rather than repeating it as established fact.

The timeline

  1. 2014 — Attackers compromise the Starwood guest reservation system.
  2. November 2015 — Starwood discloses a separate malware incident affecting payment systems at some properties.
  3. September 2016 — Marriott completes its acquisition of Starwood.
  4. 2016–2018 — The inherited Starwood platform continues in service; the compromise continues undetected.
  5. 8 September 2018 — An internal tool alerts on an access attempt against the Starwood database.
  6. 30 November 2018 — Marriott discloses: up to 500 million records.
  7. 4 January 2019 — The estimate is revised to around 339 million, with passport and card detail broken out.
  8. July 2019 — The UK ICO issues a notice of intent to fine £99 million.
  9. October 2020 — The final penalty is set at £18.4 million.

What it changed

Security due diligence entered the deal process. Before Marriott, technical due diligence in an acquisition meant systems, licences and technical debt. Afterwards, "has the target been compromised, and how would we know?" became a standard pre-close question, with compromise assessments commissioned as part of diligence. The reasoning is simple and expensive: you inherit the breach along with the balance sheet, and you inherit the regulatory liability for it too.

Legacy platform migration acquired urgency. Running an acquired company's systems in parallel for years is normal, and it is also a period in which nobody quite owns them. Marriott's case made that interim ownership gap a named risk.

Regulators showed they would discount penalties. The gap between the £99 million notice of intent and the £18.4 million final figure is one of the clearest illustrations of how European regulators weigh remediation, cooperation and circumstance. It cut both ways: campaigners read it as a regulator retreating, and practitioners read it as evidence that investing in response demonstrably reduces the bill.

If you stayed at a Starwood hotel before 2018

  1. Check whether your passport number was in the unencrypted set if you were notified. Some governments and Marriott itself offered to cover replacement costs where fraud could be shown.
  2. Assume your travel dates are known. There is no remediation for that, but it changes how you should read a message that references a trip you actually took — familiarity is not authentication.
  3. Watch for travel-themed phishing. Loyalty account takeovers and "problem with your booking" messages are the direct downstream use of this data.
  4. Review what your loyalty accounts still hold. Old profiles accumulate passport details, addresses and card tokens long after the trip — clearing out what you no longer need is the only control you hold yourself.

Checked against every breach on record, against public breach data only. Your address is not sent to us as a form and is not stored — it is handed straight to the lookup tool in your own browser. See the privacy policy.

Questions people ask

How many people were affected by the Marriott breach?

Marriott's first statement said up to 500 million guest records. A revised estimate in January 2019 put it at around 339 million, of which roughly 5.25 million contained unencrypted passport numbers and about 20.3 million contained encrypted ones. Records are not people: frequent travellers appear many times.

Why does a travel record matter more than it sounds?

Because it is a movement history. Names, passport numbers, arrival and departure dates and hotel locations, held over four years, reconstruct who was where and when — and, by correlation, who was there at the same time. For most travellers that is a privacy loss. For diplomats, executives and intelligence officers it is an operational one, which is why this breach was read as espionage rather than fraud.

Did the breach start before Marriott owned Starwood?

Yes. The compromise of the Starwood reservation system dates to 2014; Marriott completed its acquisition of Starwood in 2016 and continued operating the inherited system until 2018. That sequence is why this case is cited in every discussion of cybersecurity due diligence in mergers and acquisitions.

What was the fine?

The UK Information Commissioner's Office issued a notice of intent to fine Marriott £99 million in 2019 and settled on £18.4 million in October 2020, reducing it for remediation and for the economic impact of the pandemic. It remains one of the larger GDPR penalties issued by the UK regulator.

Sources

Read next

Case files are written from the public record: regulatory findings, court filings, company disclosures and contemporaneous reporting, cited above. Figures are the ones the organisation or its regulator finally settled on, which is often not the number first reported — where that differs, the page says so. Disputed accounts are marked as disputed rather than resolved in either direction.

← All case files Breach archive →