Marriott International
Disclosed Nov 30, 20187 years ago500,000,000 affectedSettled
Starwood reservation database breach; UK ICO fine, FTC order and USD 52M states settlement
Attackers had been in Starwood's guest reservation database since 2014, before Marriott bought Starwood, exposing up to 339 million guest records including passport numbers until discovery in November 2018. The ICO issued a final fine of about USD 23.8M in October 2020, down from a proposed GBP 99M, and in October 2024 the FTC ordered a security program while 50 attorneys general secured USD 52M over this and other breaches.
What is known
| People affected | 500,000,000 (as reported by the organization) |
|---|---|
| Disclosed | Nov 30, 2018 |
| Discovered | Nov 19, 2018 |
| Happened | Sep 10, 2018 |
| Attack | Hacking |
| Data exposed | Names, Addresses, Phone numbers, Emails, Government IDs, Dates of birth, Payment cards, Other, Financial |
| Sector | Hospitality · US |
| Status | Settled |
| Lawsuit or fine | ICO fine of about USD 23.8M (Oct 2020); USD 52M multistate AG settlement and FTC order (Oct 2024) (about $76M) |
Sources
Notices filed
| Where | Filed | People |
|---|---|---|
| California AGresidents of CA | Nov 30, 2018 | |
| Oregon DOJresidents of OR | Nov 30, 2018 | 500,000,000 |
| Researchtotal | Nov 30, 2018 | 500,000,000 |
| Researchtotal | Nov 30, 2018 | |
| Indiana AGresidents of IN | Nov 30, 2018 | 500,000,000 |
| Maine AGresidents of ME | Nov 30, 2018 |
Other breaches at Marriott International
| Breach | Affected | ||||
|---|---|---|---|---|---|
| Social engineering at a Marriott hotel leads to theft of guest and card dataJul 6, 20224 years agoPhishingUnverified | Jul 6, 20224 years ago | Phishing | Hospitality | Unverified | Unknown |
| Disclosed Oct 30, 2019Oct 30, 20196 years ago | Oct 30, 20196 years ago | Not stated | Hospitality | Confirmed | 2,589 |
| Disclosed Oct 16, 2017Oct 16, 20178 years ago | Oct 16, 20178 years ago | Not stated | Hospitality | Confirmed | 75 |
| Disclosed Oct 19, 2015Oct 19, 201510 years ago | Oct 19, 201510 years ago | Not stated | Hospitality | Confirmed | 70 |
History of this record
- 2026-09-25 · notice_affected: empty to in-ag: 500000000 (restored: the portal's own figure) · correction source
- 2026-09-25 · notice_affected: empty to or-doj: 500000000 (restored: the portal's own figure) · correction source
- 2026-09-25 · notice_affected: in-ag: 500000000 to · correction source
- 2026-09-25 · notice_affected: or-doj: 500000000 to · correction source
- 2026-09-25 · data_types: ["names","addresses","phone","emails","government-id","dob","payment-card","other"] to ["names","addresses","phone","emails","government-id","dob","payment-card","other","financial"] · backfill source
- 2026-09-25 · source: empty to https://www.in.gov/attorneygeneral/consumer-protection-division/id-theft-prevention/files/DB-Year-to-date-Report-2018.pdf · backfill source
- 2026-09-25 · fine_usd: empty to 75800000 · seed source
- 2026-09-25 · lawsuit: 18.4M GBP ICO GDPR fine (2020) to ICO fine of about USD 23.8M (Oct 2020); USD 52M multistate AG settlement and FTC order (Oct 2024) · seed source
- 2026-09-25 · data_types: ["names","addresses","phone","emails","government-id","dob","payment-card"] to ["names","addresses","phone","emails","government-id","dob","payment-card","other"] · seed source
- 2026-09-25 · summary: Marriott said there had been unauthorized access to the Starwood guest reservation network since 2014, affecting up to about 500 million guests; for about 327 million the data included passport numbers and other details, and some records he to Attackers had been in Starwood's guest reservation database since 2014, before Marriott bought Starwood, exposing up to 339 million guest records including passport numbers until discovery in November 2018. The ICO issued a final fine of ab · seed source
- 2026-09-25 · title: Starwood reservation database breach exposes up to 500 million guests to Starwood reservation database breach; UK ICO fine, FTC order and USD 52M states settlement · seed source
- 2026-09-25 · status: confirmed to settled · seed source
- 2026-09-25 · lawsuit: empty to 18.4M GBP ICO GDPR fine (2020) · seed source
- 2026-09-25 · attack: unknown to hacking · seed source
- 2026-09-25 · data_types: [] to ["names","addresses","phone","emails","government-id","dob","payment-card"] · seed source
- 2026-09-25 · records_basis: empty to organization · seed source
- 2026-09-25 · records: empty to 500000000 · seed source
- 2026-09-25 · summary: empty to Marriott said there had been unauthorized access to the Starwood guest reservation network since 2014, affecting up to about 500 million guests; for about 327 million the data included passport numbers and other details, and some records he · seed source
- 2026-09-25 · title: empty to Starwood reservation database breach exposes up to 500 million guests · seed source
- 2026-09-25 · discovered: empty to 2018-11-19 · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.