Marriott Acquired Starwood's Reservation System in 2016 Without Noticing Chinese State-Linked Hackers Had Already Been Inside It for Two Years. Its 2024 Settlement Requires Learning the Due Diligence That Was Supposed to Catch That the First Time.
In July 2014, attackers later assessed by U.S. investigators as linked to China's Ministry of State Security got into Starwood Hotels & Resorts' guest reservation database. They stayed. In September 2016, Marriott completed its acquisition of Starwood for roughly $13 billion, absorbing the reservation system, the loyalty program, the hotel portfolio — and the intrusion already running inside it. Due diligence didn't catch it. Neither did the post-merger IT integration that followed.
The breach ran undetected for another two years after the acquisition closed, discovered only on September 8, 2018, when an internal security tool flagged suspicious database activity. Marriott disclosed it publicly on November 30, 2018 — four years, four months after the initial compromise. By then the exposure ran to hundreds of millions of guests, a decryption key Marriott says was never proven stolen, and a due-diligence failure that would take a decade of regulatory proceedings, on two continents, to fully price.
Four Years Inside
The scale of what the intrusion touched only came into focus after disclosure, and it kept shifting downward on guest count and upward on sensitivity.
- Initial November 2018 estimate: up to 500 million guest records exposed.
- Revised figure: approximately 383 million unique guests.
- Data included names, addresses, phone numbers, email addresses, dates of birth, gender, and arrival/departure information.
- For a subset of guests: passport numbers — 5.25 million unencrypted, 20.3 million encrypted.
- Payment card data: roughly 8.6 million encrypted card numbers, of which 354,000 were still unexpired at the time of disclosure.
- Marriott said there was no evidence the master decryption key needed to unlock the encrypted card and passport data had also been taken.
The Merger That Missed It
Marriott's $13 billion acquisition of Starwood was one of the largest hotel deals in history, folding Starwood's Sheraton, Westin, and St. Regis brands — and its SPG loyalty database — into Marriott's portfolio. Standard acquisition practice calls for technical due diligence on the target's IT systems, including security posture, before close. Standard practice also calls for a security review during post-merger integration, when two companies' networks are actually stitched together.
Both steps happened. Neither one surfaced an intrusion that, by the time the deal closed in September 2016, had already been running inside Starwood's reservation database for more than two years. The compromised system didn't just survive the acquisition — it survived being audited for the acquisition.
The Price of Not Catching It
The regulatory bill arrived in stages, on both sides of the Atlantic, and it kept getting revised as the pandemic and Marriott's cooperation record entered the calculus.
- July 2019: the UK Information Commissioner's Office proposed a £99.2 million fine under GDPR.
- October 2020: the ICO reduced the fine to £18.4 million, citing Marriott's cooperation, its remediation steps, and the impact of COVID-19 on the hospitality sector.
- October 9, 2024: the FTC and a coalition of 50 state attorneys general settled with Marriott for $52 million, covering breaches spanning 2014 to 2020.
- The 2024 settlement also mandated data deletion, a risk-based information security program, and ongoing oversight of vendors and franchisees.
What the Settlement Actually Requires
Buried in the FTC and state attorneys general order is a line item that names the failure directly: Marriott is now required to improve its due-diligence practices for future acquisitions. Not its firewalls, not its encryption standard alone — its process for vetting what it buys.
In March 2019 Senate testimony, then-CEO Arne Sorenson had already promised a version of this fix, pledging a "layered defense" built on "encryption and decentralized storage." He also apologized publicly: "We fell short of what our guests deserve." Both the apology and the pledge came after four years of undetected access to a system that, evidently, had not been layered, decentralized, or defended enough to notice an intruder who had been there since before the acquisition was even announced.
Timeline
- July 2014 — Unauthorized access to Starwood's guest reservation database begins.
- September 2016 — Marriott completes its acquisition of Starwood; the compromised system is absorbed undetected.
- September 8, 2018 — An internal security tool flags suspicious database activity, triggering investigation.
- November 30, 2018 — Marriott publicly discloses the breach.
- March 2019 — Sorenson testifies before the Senate, pledges layered, decentralized defenses.
- July 2019 — ICO proposes a £99.2 million GDPR fine.
- October 2020 — ICO reduces the fine to £18.4 million.
- October 9, 2024 — FTC and 50-state coalition settle for $52 million, with mandated acquisition due-diligence reforms going forward.
The 2024 settlement requires Marriott to build a due-diligence process for evaluating the security of companies it acquires. Due diligence is also, by definition, the process that was supposed to happen before Marriott bought a hotel chain whose reservation system a state-linked intelligence service had already been inside for over two years.
Filed from public reporting:
- CNBC — "Marriott says its Starwood database was breached on approximately 500 million guests"
- CSO Online — "Marriott data breach FAQ: How did it happen and what was the impact?"
- CNN Business — "New York Times: Chinese hackers behind massive Marriott breach"
- MIT Technology Review — "The US suspects Chinese state hackers are behind the Marriott hotel data breach"
- CyberScoop — "Marriott says 25 million passport numbers, some unencrypted, involved in massive breach"
- EDPB — "ICO statement: intention to fine Marriott International Inc more than £99 million under GDPR"
- Computer Weekly — "ICO slashes Marriott breach fine to £18.4m"
- National Law Review — "FTC and Coalition of State Attorneys General Announce Settlements with Marriott Over Guest Data Breaches"
- Cybersecurity Dive — "FTC settles yearslong investigation into Marriott's 'security failures'"
- Connecticut Attorney General — "Multistate Settlement with Marriott for Data Breach of Starwood Guest Reservation Database"