Don’t do SECURITY. Do business SECURELY.

Marriott reveals Starwood breach affecting up to 500 million guests

Marriott disclosed that attackers had access to its Starwood guest reservation database since 2014, exposing data on up to 500 million guests.

Marriott International disclosed that attackers had gained unauthorised access to the Starwood guest reservation database, which it had acquired in 2016. It initially said up to around 500 million guests could be affected. Starwood brands included Sheraton, Westin, and W Hotels.

What happened

  • The intrusion dated back to 2014, before Marriott bought Starwood, and was discovered in September 2018.
  • Data included names, addresses, phone numbers, email addresses, passport numbers, and, for some guests, encrypted payment card details.
  • Marriott later revised the figure to around 383 million guest records.
  • The UK ICO fined Marriott £18.4m in 2020, and media reports linked the attack to Chinese state-backed hackers, which China denied.

Why it mattered

It was one of the largest breaches ever disclosed and highlighted the security risks that companies inherit through mergers and acquisitions. Marriott later said more than five million unencrypted passport numbers were involved.

Lessons for organisations

Carry out cyber security due diligence before acquisitions, integrate or replace acquired systems quickly, and minimise retention of sensitive data such as passport numbers. Detection tools should also be reviewed so that long-running intrusions are found sooner.

Source: CNN

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights