01Summary
The breach, which was discovered in late 2018, affected the combined guest databases of Marriott and its acquired brand, Starwood. Security researchers and subsequent investigations revealed that the attackers maintained persistent access to the network for an extended period. The primary method of compromise involved exploiting vulnerabilities within the interconnected systems, allowing the threat actors to systematically harvest vast quantities of PII. The data volume was staggering, encompassing records from millions of guests across multiple countries. The incident prompted global regulatory scrutiny, particularly regarding compliance with GDPR and CCPA, and forced Marriott to undertake massive, costly security overhauls.
02Background
Marriott International acquired Starwood Hotels & Resorts in 2016, integrating two massive, complex, and historically separate IT infrastructures. This rapid integration created a sprawling and difficult-to-secure digital environment. The complexity of merging these two global systems provided a large attack surface, which the threat actors were able to exploit over time.
03Key revelations
- 01The breach exposed the PII of hundreds of millions of global travelers, spanning multiple jurisdictions.
- 02The attack was attributed to a sophisticated, state-sponsored group (APT40), indicating espionage motives.
- 03The incident revealed systemic weaknesses in the IT integration process following the acquisition of Starwood by Marriott.
04Technical analysis
The attackers utilized sophisticated techniques, including credential harvesting and lateral movement, to access the core databases. While the passwords were reportedly encrypted, the sheer volume of PII—including names, addresses, and phone numbers—was sufficient for targeted phishing campaigns and identity theft. The breach was attributed to state-sponsored actors, suggesting a motive beyond simple financial gain, pointing toward intelligence collection.
- Attack vector
- Exploitation of vulnerabilities within the interconnected Marriott/Starwood IT infrastructure.
- Attack method
- Persistent network intrusion and data exfiltration.
- Initial access
- Exploitation of network vulnerabilities or compromised credentials.
- Lateral movement
- Internal network pivoting and privilege escalation.
- Persistence
- Maintaining persistent access through backdoors or compromised accounts.
- Exfiltration
- Bulk data transfer over the network to external command and control infrastructure.
- Malware type
- Stealer / Backdoor
Vulnerabilities exploited
- Unknown (Systemic vulnerability in merged infrastructure)
MITRE ATT&CK techniques
- T1078
- T1566.001
05Threat actor
APT40 is a sophisticated, state-sponsored threat group widely attributed to China's Ministry of State Security (MSS). They are known for conducting targeted espionage campaigns, often focusing on intellectual property, military technology, and sensitive corporate data from Western entities.
Aliases
- Chinese MSS
- Fancy Bear
APT designations
- APT40
MITRE groups
- T1078
- T1566.001
Attribution sources
- Mandiant
- FireEye
- Reuters
06Victims and impact
Additional victims
- Starwood Hotels & Resorts
Countries affected
- USA
- UK
- Australia
07Data exposed
Data types
- Names
- Email Addresses
- Phone Numbers
- Encrypted Passwords
- Travel History
Notable documents
- Guest Profile Databases
- Starwood/Marriott User Records
08Financial damage
Estimated costs include regulatory fines, mandatory security upgrades, and class-action lawsuit settlements.
09Timeline
- 2016-01-01Marriott acquires Starwood Hotels & Resorts, beginning the complex IT integration process.
- 2018-11-30The initial unauthorized access and data exfiltration period begins.
- 2018-12-17The breach is publicly disclosed by Marriott, following discovery by security researchers.
10Key figures
- Marriott InternationalVictim Organization · Marriott International, Inc.Mandated significant security overhauls and faced regulatory fines.
11On the record
We are working with leading external cybersecurity experts to investigate the scope and nature of the breach.
12Reaction and fallout
Public reaction
The public reaction was characterized by widespread concern over identity theft and the perceived lack of adequate data protection measures by major corporations. Consumer advocacy groups demanded stricter global data governance standards.
Political impact
The breach intensified global regulatory focus on data privacy, accelerating discussions around stricter enforcement of GDPR and similar consumer protection laws in the hospitality sector.
Geopolitical consequences
The attribution to APT40 reinforced the growing geopolitical tension regarding cyber espionage, particularly concerning the theft of Western corporate and personal data by Chinese state actors.
13Legal
The incident led to multiple class-action lawsuits and required Marriott to undergo extensive, costly, and publicly scrutinized security audits and upgrades.
Civil lawsuits
- Class-action lawsuits filed by affected consumers in multiple jurisdictions.
14Aftermath
Policy changes
- Increased scrutiny of cross-border data transfer protocols in the hospitality industry.
- Mandatory, independent third-party security audits for large-scale data processors.
Regulatory changes
- Increased enforcement actions by European Data Protection Authorities (DPAs) regarding data breach notification timelines.
Security improvements
- Implementation of advanced encryption standards for stored PII.
- Segmentation of corporate networks to prevent lateral movement between acquired systems.
15Significance and legacy
Significance
This breach is a landmark case study in the risks associated with large-scale corporate mergers and acquisitions (M&A) in the digital age. It demonstrated that the integration of disparate, legacy IT systems creates massive, exploitable attack surfaces, making the resulting entity vulnerable to sophisticated, long-term state-sponsored espionage.
Legacy
The incident permanently raised the bar for corporate data security, forcing major global brands to adopt a 'security-by-design' approach. It also highlighted the difficulty of enforcing consistent data protection standards across multiple international jurisdictions.
16Disclosure and media
- Authentication
- Forensic analysis of leaked data and internal reports.
Media partners
- Reuters
- The New York Times
Publishing organisations
- Mandiant
- Reuters
18Field notes
- 01The sheer scale of the breach meant that data was collected from guests who had stayed at the properties decades prior.
- 02The investigation highlighted that the attackers were not primarily interested in immediate financial theft, but rather in the long-term intelligence value of the PII.
19Resolution
Marriott committed to a multi-year, multi-billion dollar overhaul of its global IT infrastructure and data governance policies.
20Sources
Official documents
- Mandiant Threat Report (2019)
References
- [1]Mandiant Threat Intelligence Reports
- [2]Reuters Coverage of Data Breach
- [3]GDPR Enforcement Guidelines









