Marriott Acquired Starwood's Reservation System in 2016 Without Noticing Chinese State-Linked Hackers Had Already Been Inside It for Two Years. Its 2024 Settlement Requires Learning the Due Diligence That Was Supposed to Catch That the First Time.

Share
Marriott Acquired Starwood's Reservation System in 2016 Without Noticing Chinese State-Linked Hackers Had Already Been Inside It for Two Years. Its 2024 Settlement Requires Learning the Due Diligence That Was Supposed to Catch That the First Time.
Photo by Rafael Maggion / Unsplash

In July 2014, attackers later assessed by U.S. investigators as linked to China's Ministry of State Security got into Starwood Hotels & Resorts' guest reservation database. They stayed. In September 2016, Marriott completed its acquisition of Starwood for roughly $13 billion, absorbing the reservation system, the loyalty program, the hotel portfolio — and the intrusion already running inside it. Due diligence didn't catch it. Neither did the post-merger IT integration that followed.

The breach ran undetected for another two years after the acquisition closed, discovered only on September 8, 2018, when an internal security tool flagged suspicious database activity. Marriott disclosed it publicly on November 30, 2018 — four years, four months after the initial compromise. By then the exposure ran to hundreds of millions of guests, a decryption key Marriott says was never proven stolen, and a due-diligence failure that would take a decade of regulatory proceedings, on two continents, to fully price.

Four Years Inside

The scale of what the intrusion touched only came into focus after disclosure, and it kept shifting downward on guest count and upward on sensitivity.

  • Initial November 2018 estimate: up to 500 million guest records exposed.
  • Revised figure: approximately 383 million unique guests.
  • Data included names, addresses, phone numbers, email addresses, dates of birth, gender, and arrival/departure information.
  • For a subset of guests: passport numbers — 5.25 million unencrypted, 20.3 million encrypted.
  • Payment card data: roughly 8.6 million encrypted card numbers, of which 354,000 were still unexpired at the time of disclosure.
  • Marriott said there was no evidence the master decryption key needed to unlock the encrypted card and passport data had also been taken.

The Merger That Missed It

Marriott's $13 billion acquisition of Starwood was one of the largest hotel deals in history, folding Starwood's Sheraton, Westin, and St. Regis brands — and its SPG loyalty database — into Marriott's portfolio. Standard acquisition practice calls for technical due diligence on the target's IT systems, including security posture, before close. Standard practice also calls for a security review during post-merger integration, when two companies' networks are actually stitched together.

Both steps happened. Neither one surfaced an intrusion that, by the time the deal closed in September 2016, had already been running inside Starwood's reservation database for more than two years. The compromised system didn't just survive the acquisition — it survived being audited for the acquisition.

The Price of Not Catching It

The regulatory bill arrived in stages, on both sides of the Atlantic, and it kept getting revised as the pandemic and Marriott's cooperation record entered the calculus.

  • July 2019: the UK Information Commissioner's Office proposed a £99.2 million fine under GDPR.
  • October 2020: the ICO reduced the fine to £18.4 million, citing Marriott's cooperation, its remediation steps, and the impact of COVID-19 on the hospitality sector.
  • October 9, 2024: the FTC and a coalition of 50 state attorneys general settled with Marriott for $52 million, covering breaches spanning 2014 to 2020.
  • The 2024 settlement also mandated data deletion, a risk-based information security program, and ongoing oversight of vendors and franchisees.

What the Settlement Actually Requires

Buried in the FTC and state attorneys general order is a line item that names the failure directly: Marriott is now required to improve its due-diligence practices for future acquisitions. Not its firewalls, not its encryption standard alone — its process for vetting what it buys.

In March 2019 Senate testimony, then-CEO Arne Sorenson had already promised a version of this fix, pledging a "layered defense" built on "encryption and decentralized storage." He also apologized publicly: "We fell short of what our guests deserve." Both the apology and the pledge came after four years of undetected access to a system that, evidently, had not been layered, decentralized, or defended enough to notice an intruder who had been there since before the acquisition was even announced.

Timeline

  • July 2014 — Unauthorized access to Starwood's guest reservation database begins.
  • September 2016 — Marriott completes its acquisition of Starwood; the compromised system is absorbed undetected.
  • September 8, 2018 — An internal security tool flags suspicious database activity, triggering investigation.
  • November 30, 2018 — Marriott publicly discloses the breach.
  • March 2019 — Sorenson testifies before the Senate, pledges layered, decentralized defenses.
  • July 2019 — ICO proposes a £99.2 million GDPR fine.
  • October 2020 — ICO reduces the fine to £18.4 million.
  • October 9, 2024 — FTC and 50-state coalition settle for $52 million, with mandated acquisition due-diligence reforms going forward.

The 2024 settlement requires Marriott to build a due-diligence process for evaluating the security of companies it acquires. Due diligence is also, by definition, the process that was supposed to happen before Marriott bought a hotel chain whose reservation system a state-linked intelligence service had already been inside for over two years.


Filed from public reporting:

Read more

Milwaukee County Required Augmented-Reality Game Publishers to Apply for Park Event Permits After Pokémon Go Crowds Overran Lake Park. The Law Was Undone by a Cowboy-Themed Poker App and Cost $83,000 in Legal Fees.

Milwaukee County Required Augmented-Reality Game Publishers to Apply for Park Event Permits After Pokémon Go Crowds Overran Lake Park. The Law Was Undone by a Cowboy-Themed Poker App and Cost $83,000 in Legal Fees.

In July 2016, Pokémon Go was released, and Lake Park, a public park on Milwaukee's East Side, turned out to be full of places the game told people to visit. Hundreds of players arrived, and sometimes thousands, at all hours. According to the Associated Press, the result was

By The Complaints Department
Panera Launched an Unlimited Self-Serve Drinks Subscription in 2022 Alongside a Lemonade With Up to 390 Milligrams of Caffeine. The Only Limit at the Fountain Was One Cup Every Two Hours.

Panera Launched an Unlimited Self-Serve Drinks Subscription in 2022 Alongside a Lemonade With Up to 390 Milligrams of Caffeine. The Only Limit at the Fountain Was One Cup Every Two Hours.

On 19 April 2022, Panera Bread launched Unlimited Sip Club, which it billed as the first nationwide unlimited subscription for self-serve beverages. For $10.99 a month, members could take one self-serve drink every two hours during café hours, refills included. The menu covered coffee, tea, fountain soda,

By The Complaints Department
The Man Who Wrote the Password Rules Said in 2017 That He Regretted Them. His Own Guideline Had Predicted in 2004 That Everyone Would Capitalize the First Letter and Put the Symbol at the End.

The Man Who Wrote the Password Rules Said in 2017 That He Regretted Them. His Own Guideline Had Predicted in 2004 That Everyone Would Capitalize the First Letter and Put the Symbol at the End.

In June 2004 the National Institute of Standards and Technology published Special Publication 800-63, the Electronic Authentication Guideline, by William Burr, Donna Dodson and Timothy Polk. It was written for US federal agencies. Its Appendix A set out a method for estimating how strong a password was, and it

By The Complaints Department
Ofo Put Millions of Yellow Bicycles on China's Streets for Anyone to Ride and Took a Small Deposit to Make Sure They Came Back. At Last Count, More Than Fifteen Million Riders Were Still Waiting for the Deposit.

Ofo Put Millions of Yellow Bicycles on China's Streets for Anyone to Ride and Took a Small Deposit to Make Sure They Came Back. At Last Count, More Than Fifteen Million Riders Were Still Waiting for the Deposit.

Ofo was founded in 2014 by Dai Wei, a Peking University graduate, and began on that university's campus. The idea was simple enough to fit on a sticker. A yellow bicycle stood on the pavement, unattended. A rider paid through an app, cycled wherever they were going, and

By The Complaints Department