Massive Marriott Data Breach Affects up to 500 Million Guests

Nov 30, 2018

This post contains references to products from one or more of our advertisers. We may receive compensation when you click on links to those products. Terms apply to the offers listed on this page. For an explanation of our Advertising Policy, visit this page.

Marriott International said Friday the data of up to 500 million of its guests has been stolen from its Starwood guest reservation database. The data breach is likely one of the largest ever in US history.

The hotel chain, which is the world’s largest, said in a release on Friday that it was first alerted to the hack in September after receiving notification from an internal security tool that there was an attempt to access customers’ data. The company started an investigation and learned that hackers have had access to Starwood guest database since 2014.

For four years, the hackers stole and encrypted customers’ personal information, creating their own database of Starwood guests’ data. It took Marriott until Nov. 19 to decode most of the breached information.

For about 327 million guests, the hackers absconded with “some combination of name, mailing address, phone number, email address, passport number, Starwood Preferred Guest (“SPG”) account information, date of birth, gender, arrival and departure information, reservation date, and communication preference,” Marriott said.

An undisclosed number of customers also had their payment card numbers and expiration dates breached. That information was encrypted in two parts, but the hotel chain said it can’t rule out that both were stolen and decoded.

For the remaining chunk of guests, the stolen information “was limited to name and sometimes other data such as mailing address, email address, or other information,” Marriott said.

“We are still investigating the situation so we don’t have a list of specific hotels. What we do know is that it only impacted Starwood brands,” Marriott spokesperson Jeff Flaherty told Reuters.

The hotel chain apologized to customers and has taken steps to address the security issues. Marriott is working with law enforcement on the breach. It also is providing affected customers with one free year of an information protection service, called WebWatcher. The company will start contacting affected customers by email on Friday.

Featured image by Roberto Machado Noa/LightRocket via Getty Images.

*This post has been updated with Marriott’s spokesperson’s comments.

The All-New United Quest℠ Card

WELCOME OFFER: Up to 100,000 bonus miles

TPG'S BONUS VALUATION*: $1,040

CARD HIGHLIGHTS: 3X miles on United® purchases

*Bonus value is an estimated value calculated by TPG and not the card issuer. View our latest valuations here.

Apply Now
More Things to Know
  • Earn 80K bonus miles after you spend $5,000 on purchases in the first 3 months your account is open. Plus, an additional 20K bonus miles after you spend $10,000 in the first 6 months
  • $250 Annual Fee
  • Earn 3X miles on United® purchases, 2X miles at restaurants, on select streaming services & all other travel, 1X on all other purchases
  • Earn 3X miles on United Airlines purchases
  • Earn 2X miles at restaurants and on select streaming services
  • Earn 2X miles on all other travel
  • Earn 1X mile on all other purchases
  • Each year, receive a $125 credit on United® purchases and two 5k-mile anniversary award flight credits. Terms apply.
Regular APR
16.49% to 23.49% Variable
Annual Fee
$250
Balance Transfer Fee
Either $5 or 5% of the amount of each transfer, whichever is greater.
Recommended Credit
Excellent, Good

Editorial Disclaimer: Opinions expressed here are the author’s alone, not those of any bank, credit card issuer, airlines or hotel chain, and have not been reviewed, approved or otherwise endorsed by any of these entities.

Disclaimer: The responses below are not provided or commissioned by the bank advertiser. Responses have not been reviewed, approved or otherwise endorsed by the bank advertiser. It is not the bank advertiser’s responsibility to ensure all posts and/or questions are answered.