Marriott International says 500M records from the guest reservation database of Starwood Hotels were stolen in a massive data breach dating as far back as 2014
Starwood Hotels has confirmed its hotel guest database of about 500 million customers has been stolen in a data breach.
Context & Ripple Effects
Marriott disclosed in late November 2018 that attackers had been inside the Starwood guest reservation database since as far back as 2014, accessing names, contact details, passport numbers, dates of birth, reservation history and some payment card data for up to 500 million guests. The company had already flagged security-breach risk in its November 6 quarterly filing before confirming the scale publicly.
First-order effects
- Up to 500 million guests face exposure of highly sensitive identity data — including passport numbers and payment card details — forcing Marriott into mass notification and remediation of a compromise that predates its disclosure by four years.
Second-order effects
- Marriott's own follow-up reporting shows how unstable the initial number was: by early January 2019 it revised the stolen total down to 383 million records, while revealing that more than 5 million passport numbers had been stored unencrypted — a correction cycle that keeps the incident in headlines and invites regulatory scrutiny of its data-handling practices.
Third-order effects
- The pattern held after this breach: Marriott disclosed another incident affecting 5.2 million guests in January 2020, suggesting that consolidated hospitality reservation systems carrying years of guest PII will keep producing large, recurring exposures until retention and encryption practices change structurally.
The trend: Hotel-industry consolidation is concentrating decades of guest identity data into single reservation platforms, turning one operator's security failure into record-scale breaches that surface years after intrusion.