What caused the Marriott breach: the intruder that came with Starwood
When Marriott bought Starwood Hotels in 2016, an intruder had already been inside Starwood's guest reservation database for 2 years, and nobody noticed for 2 more.[1] This case file covers how a hidden foothold survived a major hotel merger, how a single odd database query finally exposed it, what it cost, and the control that was missing.
What happened
In July 2014, while Starwood was still an independent company, someone got into the network behind its guest reservation system.[1] Starwood already had other security trouble in that era: the FTC says a separate breach of its payment systems starting in 2014 hit about 40,000 people, and a different attacker got into Starwood systems in 2015 and went undetected for 8 months.[3][4]
Marriott completed its purchase of Starwood on September 23, 2016.[1] It did not move Starwood's reservation database onto its own systems right away. The old database kept running, with the intruder still in it, for about 2 more years.[1][2]
On September 7, 2018, a database monitoring tool flagged a query made from an administrator's account. The next day, the contractor running Starwood's IT told Marriott that the administrator had not made it.[1][2] In November, investigators found traces of 2 encrypted, compressed files that had been removed from a device on the network, and decrypted them on November 19. They held guest reservation data.[2]
Marriott announced the breach on November 30, 2018, first estimating about 500 million guest records.[1][3] After removing duplicates it put the upper limit at about 383 million records.[2]
How they got in
The full entry point was never made public. What Marriott's chief executive told a Senate subcommittee in 2019 is that investigators found a remote access trojan, a program that lets someone control a computer from outside, along with a tool for pulling usernames and passwords out of a computer's memory.[1][2]
That second tool explains how a single foothold turned into years of access. With harvested administrator passwords, the intruder could look like a trusted insider and query the reservation database the way staff did. That is also why the eventual alert was about who ran a query, not about malware.[2]
The data taken was the kind hotels collect at check-in: names, contact details, dates of birth and loyalty account information[4]. It also included about 5.25 million passport numbers that were not encrypted, 18.5 million that were, and about 9.1 million encrypted payment card numbers.[2] Marriott said it could not rule out that the keys needed to unlock the encrypted card numbers had also been taken, though it found no evidence of that.[2]
What it cost
Marriott shut down the Starwood reservation database on December 18, 2018, moving guests onto its own system earlier than planned.[1]
In the UK, the Information Commissioner's Office proposed a fine of £99.2 million in July 2019 and settled on £18.4 million on October 30, 2020. The regulator said about 7 million UK guest records were involved and faulted Marriott for not keeping up checks on the systems it had bought.[6]
In the United States, the FTC announced a settlement on October 9, 2024, covering the Starwood breaches and a later 2020 Marriott breach of about 5.2 million guests. It accused the companies of weak passwords, missing multi-factor authentication, outdated software, poor network separation and thin monitoring.[4] The order requires a full security program and independent assessments every 2 years for 20 years.[5] On the same day, Marriott agreed to pay $52 million to 49 states and Washington, D.C., without admitting liability.[4][7]
The missing control
The missing control: security due diligence on the company being acquired, before closing and in the first months after, including a hunt for intruders already inside its systems.
When you buy a company you also buy its network, its old passwords and anyone already hiding in it. Marriott's chief executive told senators the pre-deal review was limited, in part because Starwood was a competitor until the deal closed.[1] The UK regulator's view was that this checking cannot be a one-time event and must continue after the purchase.[6] A focused compromise assessment of Starwood's reservation environment at or soon after closing, looking for unexplained remote access software and misuse of admin accounts, had a real chance of finding an intruder who had been there since 2014. The alternative was to run the old system unchanged for 2 years and wait for an alert.
What to do in your business
- Ask security questions before you buy. Before acquiring a business, merging with a practice or taking over a client book, ask for its past breaches, who has admin access and what logs it keeps. Put the answers in the deal file.
- Treat inherited systems as untrusted. On day 1, change every admin password on the systems you take over and remove accounts nobody can explain.
- Pay for a check-up, not just a migration. Have an IT provider look for signs of existing compromise, such as unknown remote access tools or strange logins, before you connect the new systems to yours.
- Set a retirement date for old systems. Decide when the inherited database, website or email server will be shut down, and hold to it.
- Watch who touches customer data. Turn on alerts for bulk exports or unusual queries on your customer list or booking system, and have someone confirm odd activity with the account owner.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: How to manage vendor, IT provider and contractor access to your systems
- How the Target breach happened: a vendor's billing login and the alarms nobody answered
- How the SolarWinds hack happened: malware shipped as a trusted update
- How the Bybit hack happened: a vendor's laptop and a screen that lied
- The C&M Software hack: a sold login and $140 million from Brazil's bank reserves
- How the Caesars hack happened: a con at the outsourced IT help desk
- How the $45 million ATM heist worked: prepaid cards with no limits
- Every vendors and third parties control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- U.S. Senate Permanent Subcommittee on Investigations: Testimony of Arne Sorenson, Marriott International (March 7, 2019)
- Help Net Security: Marriott CEO reveals more details about the massive data breach
- CSO Online: Marriott data breach FAQ: How did it happen and what was the impact?
- Perkins Coie: FTC and state coalition settle data breach cases with Marriott
- BleepingComputer: FTC orders Marriott and Starwood to implement strict data security
- Mayer Brown: Marriott International Inc fined £18.4m for personal data breach by the UK ICO under the GDPR
- WBAY (Associated Press): Marriott agrees to pay $52 million, beef up data security to resolve probes over data breaches