Skip to content

Marriott International

Disclosed Nov 30, 20187 years ago500,000,000 affectedSettled

Official notice

Starwood reservation database breach; UK ICO fine, FTC order and USD 52M states settlement

Attackers had been in Starwood's guest reservation database since 2014, before Marriott bought Starwood, exposing up to 339 million guest records including passport numbers until discovery in November 2018. The ICO issued a final fine of about USD 23.8M in October 2020, down from a proposed GBP 99M, and in October 2024 the FTC ordered a security program while 50 attorneys general secured USD 52M over this and other breaches.

What is known

People affected500,000,000 (as reported by the organization)
DisclosedNov 30, 2018
DiscoveredNov 19, 2018
HappenedSep 10, 2018
AttackHacking
Data exposedNames, Addresses, Phone numbers, Emails, Government IDs, Dates of birth, Payment cards, Other, Financial
SectorHospitality · US
StatusSettled
Lawsuit or fineICO fine of about USD 23.8M (Oct 2020); USD 52M multistate AG settlement and FTC order (Oct 2024) (about $76M)

Sources

Notices filed

WhereFiledPeople
California AGresidents of CANov 30, 2018
Oregon DOJresidents of ORNov 30, 2018500,000,000
ResearchtotalNov 30, 2018500,000,000
ResearchtotalNov 30, 2018
Indiana AGresidents of INNov 30, 2018500,000,000
Maine AGresidents of MENov 30, 2018

Other breaches at Marriott International

BreachAffected
Social engineering at a Marriott hotel leads to theft of guest and card dataJul 6, 20224 years agoPhishingUnverifiedUnknown
Disclosed Oct 30, 2019Oct 30, 20196 years ago2,589
Disclosed Oct 16, 2017Oct 16, 20178 years ago75
Disclosed Oct 19, 2015Oct 19, 201510 years ago70
History of this record
  • 2026-09-25 · notice_affected: empty to in-ag: 500000000 (restored: the portal's own figure) · correction source
  • 2026-09-25 · notice_affected: empty to or-doj: 500000000 (restored: the portal's own figure) · correction source
  • 2026-09-25 · notice_affected: in-ag: 500000000 to · correction source
  • 2026-09-25 · notice_affected: or-doj: 500000000 to · correction source
  • 2026-09-25 · data_types: ["names","addresses","phone","emails","government-id","dob","payment-card","other"] to ["names","addresses","phone","emails","government-id","dob","payment-card","other","financial"] · backfill source
  • 2026-09-25 · source: empty to https://www.in.gov/attorneygeneral/consumer-protection-division/id-theft-prevention/files/DB-Year-to-date-Report-2018.pdf · backfill source
  • 2026-09-25 · fine_usd: empty to 75800000 · seed source
  • 2026-09-25 · lawsuit: 18.4M GBP ICO GDPR fine (2020) to ICO fine of about USD 23.8M (Oct 2020); USD 52M multistate AG settlement and FTC order (Oct 2024) · seed source
  • 2026-09-25 · data_types: ["names","addresses","phone","emails","government-id","dob","payment-card"] to ["names","addresses","phone","emails","government-id","dob","payment-card","other"] · seed source
  • 2026-09-25 · summary: Marriott said there had been unauthorized access to the Starwood guest reservation network since 2014, affecting up to about 500 million guests; for about 327 million the data included passport numbers and other details, and some records he to Attackers had been in Starwood's guest reservation database since 2014, before Marriott bought Starwood, exposing up to 339 million guest records including passport numbers until discovery in November 2018. The ICO issued a final fine of ab · seed source
  • 2026-09-25 · title: Starwood reservation database breach exposes up to 500 million guests to Starwood reservation database breach; UK ICO fine, FTC order and USD 52M states settlement · seed source
  • 2026-09-25 · status: confirmed to settled · seed source
  • 2026-09-25 · lawsuit: empty to 18.4M GBP ICO GDPR fine (2020) · seed source
  • 2026-09-25 · attack: unknown to hacking · seed source
  • 2026-09-25 · data_types: [] to ["names","addresses","phone","emails","government-id","dob","payment-card"] · seed source
  • 2026-09-25 · records_basis: empty to organization · seed source
  • 2026-09-25 · records: empty to 500000000 · seed source
  • 2026-09-25 · summary: empty to Marriott said there had been unauthorized access to the Starwood guest reservation network since 2014, affecting up to about 500 million guests; for about 327 million the data included passport numbers and other details, and some records he · seed source
  • 2026-09-25 · title: empty to Starwood reservation database breach exposes up to 500 million guests · seed source
  • 2026-09-25 · discovered: empty to 2018-11-19 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Marriott International

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.