EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/marriott-starwood-breach-2018
217/430

File EL-0214CriticalResolvedData Breach / Credential Theft / PII Exfiltration

Marriott Starwood Hotels Guest Database Breach

Also filed as Starwood Hotels Breach · Marriott International Data Breach

The breach involved the unauthorized access and exfiltration of massive amounts of guest data from Marriott International's combined Starwood and Marriott systems. The compromised data included names, email addresses, phone numbers, and encrypted passwords belonging to hundreds of millions of users. This incident highlighted significant vulnerabilities in global hospitality data management and exposed users to potential identity theft.

  • #marriott
  • #starwood
  • #pii
  • #apt40
  • #chinese-espionage
  • #gdpr
Notoriety9/10
Event
30 Nov 2018
Disclosed
17 Dec 2018
Target
Marriott International
Actor
APT40
Scale
Hundreds of millions of records
Status
Resolved

01Summary

The breach, which was discovered in late 2018, affected the combined guest databases of Marriott and its acquired brand, Starwood. Security researchers and subsequent investigations revealed that the attackers maintained persistent access to the network for an extended period. The primary method of compromise involved exploiting vulnerabilities within the interconnected systems, allowing the threat actors to systematically harvest vast quantities of PII. The data volume was staggering, encompassing records from millions of guests across multiple countries. The incident prompted global regulatory scrutiny, particularly regarding compliance with GDPR and CCPA, and forced Marriott to undertake massive, costly security overhauls.

02Background

Marriott International acquired Starwood Hotels & Resorts in 2016, integrating two massive, complex, and historically separate IT infrastructures. This rapid integration created a sprawling and difficult-to-secure digital environment. The complexity of merging these two global systems provided a large attack surface, which the threat actors were able to exploit over time.

03Key revelations

  1. 01The breach exposed the PII of hundreds of millions of global travelers, spanning multiple jurisdictions.
  2. 02The attack was attributed to a sophisticated, state-sponsored group (APT40), indicating espionage motives.
  3. 03The incident revealed systemic weaknesses in the IT integration process following the acquisition of Starwood by Marriott.

04Technical analysis

The attackers utilized sophisticated techniques, including credential harvesting and lateral movement, to access the core databases. While the passwords were reportedly encrypted, the sheer volume of PII—including names, addresses, and phone numbers—was sufficient for targeted phishing campaigns and identity theft. The breach was attributed to state-sponsored actors, suggesting a motive beyond simple financial gain, pointing toward intelligence collection.

Attack vector
Exploitation of vulnerabilities within the interconnected Marriott/Starwood IT infrastructure.
Attack method
Persistent network intrusion and data exfiltration.
Initial access
Exploitation of network vulnerabilities or compromised credentials.
Lateral movement
Internal network pivoting and privilege escalation.
Persistence
Maintaining persistent access through backdoors or compromised accounts.
Exfiltration
Bulk data transfer over the network to external command and control infrastructure.
Malware type
Stealer / Backdoor

Vulnerabilities exploited

  • Unknown (Systemic vulnerability in merged infrastructure)

MITRE ATT&CK techniques

  • T1078
  • T1566.001

05Threat actor

APT40 is a sophisticated, state-sponsored threat group widely attributed to China's Ministry of State Security (MSS). They are known for conducting targeted espionage campaigns, often focusing on intellectual property, military technology, and sensitive corporate data from Western entities.

Aliases

  • Chinese MSS
  • Fancy Bear

APT designations

  • APT40

MITRE groups

  • T1078
  • T1566.001

Attribution sources

  • Mandiant
  • FireEye
  • Reuters

06Victims and impact

Additional victims

  • Starwood Hotels & Resorts

Countries affected

  • USA
  • UK
  • Australia

07Data exposed

Data types

  • Names
  • Email Addresses
  • Phone Numbers
  • Encrypted Passwords
  • Travel History

Notable documents

  • Guest Profile Databases
  • Starwood/Marriott User Records

08Financial damage

Estimated costs include regulatory fines, mandatory security upgrades, and class-action lawsuit settlements.

09Timeline

  1. 2016-01-01Marriott acquires Starwood Hotels & Resorts, beginning the complex IT integration process.
  2. 2018-11-30The initial unauthorized access and data exfiltration period begins.
  3. 2018-12-17The breach is publicly disclosed by Marriott, following discovery by security researchers.

10Key figures

  • Marriott InternationalVictim Organization · Marriott International, Inc.Mandated significant security overhauls and faced regulatory fines.

11On the record

We are working with leading external cybersecurity experts to investigate the scope and nature of the breach.

Marriott Spokesperson, Initial public statements following the discovery of the breach.

12Reaction and fallout

Public reaction

The public reaction was characterized by widespread concern over identity theft and the perceived lack of adequate data protection measures by major corporations. Consumer advocacy groups demanded stricter global data governance standards.

Political impact

The breach intensified global regulatory focus on data privacy, accelerating discussions around stricter enforcement of GDPR and similar consumer protection laws in the hospitality sector.

Geopolitical consequences

The attribution to APT40 reinforced the growing geopolitical tension regarding cyber espionage, particularly concerning the theft of Western corporate and personal data by Chinese state actors.

13Legal

The incident led to multiple class-action lawsuits and required Marriott to undergo extensive, costly, and publicly scrutinized security audits and upgrades.

Civil lawsuits

  • Class-action lawsuits filed by affected consumers in multiple jurisdictions.

14Aftermath

Policy changes

  • Increased scrutiny of cross-border data transfer protocols in the hospitality industry.
  • Mandatory, independent third-party security audits for large-scale data processors.

Regulatory changes

  • Increased enforcement actions by European Data Protection Authorities (DPAs) regarding data breach notification timelines.

Security improvements

  • Implementation of advanced encryption standards for stored PII.
  • Segmentation of corporate networks to prevent lateral movement between acquired systems.

15Significance and legacy

Significance

This breach is a landmark case study in the risks associated with large-scale corporate mergers and acquisitions (M&A) in the digital age. It demonstrated that the integration of disparate, legacy IT systems creates massive, exploitable attack surfaces, making the resulting entity vulnerable to sophisticated, long-term state-sponsored espionage.

Legacy

The incident permanently raised the bar for corporate data security, forcing major global brands to adopt a 'security-by-design' approach. It also highlighted the difficulty of enforcing consistent data protection standards across multiple international jurisdictions.

16Disclosure and media

Authentication
Forensic analysis of leaked data and internal reports.

Media partners

  • Reuters
  • The New York Times

Publishing organisations

  • Mandiant
  • Reuters

17Related files

Related events

  • Starwood Hotels & Resorts acquisition by Marriott (2016)

18Field notes

  1. 01The sheer scale of the breach meant that data was collected from guests who had stayed at the properties decades prior.
  2. 02The investigation highlighted that the attackers were not primarily interested in immediate financial theft, but rather in the long-term intelligence value of the PII.

19Resolution

Marriott committed to a multi-year, multi-billion dollar overhaul of its global IT infrastructure and data governance policies.

20Sources

Official documents

  • Mandiant Threat Report (2019)

References

  1. [1]Mandiant Threat Intelligence Reports
  2. [2]Reuters Coverage of Data Breach
  3. [3]GDPR Enforcement Guidelines
Fact sheetEL-0214

Dates

Event
30 Nov 2018
Started
30 Nov 2018
Discovered
17 Dec 2018
Disclosed
17 Dec 2018
Ongoing
No

Target

Organisation
Marriott International, Inc.
Type
Corporation
Sector
Hospitality/Travel
Country
USA

Actor

Name
APT40
Type
Nation-State Actor
Nationality
China
Nation-state
China
Affiliation
Ministry of State Security (MSS)
Motivation
Espionage and theft of personal identifiable information (PII) for intelligence gathering.
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

Volume
Hundreds of millions of records
Sensitivity
Confidential
Published
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.