Multi-CloudIncident TeardownsRetrospectives

Marriott-Starwood (Nov 2018): A Four-Year Intrusion Inherited Through Acquisition

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from November 2018, written in 2026 with the benefit of hindsight.

On November 30, 2018, Marriott International announced that attackers had accessed the guest reservation database of its Starwood brands. The intrusion had begun in 2014 — two years before Marriott acquired Starwood.

What was taken

Marriott initially estimated up to 500 million guest records, later revising the figure to around 383 million unique guests. Data included names, addresses, phone numbers, email addresses, passport numbers, dates of birth and reservation details. Some payment card data was encrypted, but Marriott could not rule out that the decryption keys were also taken.

How it went undetected

The attackers had been inside Starwood's network for about four years. Marriott inherited the compromised environment through the acquisition and continued operating the Starwood reservation system without discovering the intrusion. It was finally detected when a security tool flagged a suspicious database query in September 2018.

Consequences

The UK Information Commissioner's Office fined Marriott £18.4 million, noting failures in due diligence and in securing the systems after the acquisition. US regulators later reached settlements requiring security improvements.

Lessons in hindsight

  • Acquisitions inherit breaches. Security due diligence must look for signs of existing compromise, not just policy gaps.
  • Long dwell time is the real danger. Four years undetected allowed massive data collection.
  • Monitoring legacy systems matters as much as new ones.
  • Integrate or isolate quickly. Acquired environments should be assessed and either secured to your standard or segmented.

Marriott became a reference case for M&A cybersecurity — and for how regulators view the responsibility of an acquiring company.

marriott data breachMarriott/Starwood2018

More on this story