Marriott-Starwood (Nov 2018): A Four-Year Intrusion Inherited Through Acquisition
Retrospective: this article looks back at events from November 2018, written in 2026 with the benefit of hindsight.
On November 30, 2018, Marriott International announced that attackers had accessed the guest reservation database of its Starwood brands. The intrusion had begun in 2014 — two years before Marriott acquired Starwood.
What was taken
Marriott initially estimated up to 500 million guest records, later revising the figure to around 383 million unique guests. Data included names, addresses, phone numbers, email addresses, passport numbers, dates of birth and reservation details. Some payment card data was encrypted, but Marriott could not rule out that the decryption keys were also taken.
How it went undetected
The attackers had been inside Starwood's network for about four years. Marriott inherited the compromised environment through the acquisition and continued operating the Starwood reservation system without discovering the intrusion. It was finally detected when a security tool flagged a suspicious database query in September 2018.
Consequences
The UK Information Commissioner's Office fined Marriott £18.4 million, noting failures in due diligence and in securing the systems after the acquisition. US regulators later reached settlements requiring security improvements.
Lessons in hindsight
- Acquisitions inherit breaches. Security due diligence must look for signs of existing compromise, not just policy gaps.
- Long dwell time is the real danger. Four years undetected allowed massive data collection.
- Monitoring legacy systems matters as much as new ones.
- Integrate or isolate quickly. Acquired environments should be assessed and either secured to your standard or segmented.
Marriott became a reference case for M&A cybersecurity — and for how regulators view the responsibility of an acquiring company.
- How to Run a Cloud Security Due Diligence Review During M&A How-To & Hardening
- Hunting for Long-Dwell Intruders in Cloud and Hybrid Environments Detection & Response
- CIO Brief: When You Buy a Company, You Buy Its Breaches CIO Briefings