Marriott Starwood 383 Million Guest Reservation Breach
Key Facts
- Legal Status: SETTLED in U.S. District Court for the District of Maryland.
- Primary Target Sector: Hospitality & Travel.
- Documented Financial Loss: $250.0 million.
- 3 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Undetected legacy compromise of the Starwood Hotels & Resorts guest reservation database network dating back to 2014, inherited by Marriott International during its 2016 corporate acquisition.
Operational & Financial Fallout
Unauthorized access to approximately 383 million guest records, including names, mailing addresses, phone numbers, passport numbers, travel details, and encrypted payment card numbers, resulting in a GBP 18.4M UK ICO GDPR fine and extensive global regulatory investigations.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Undetected legacy compromise of the Starwood Hotels & Resorts guest reservation database network dating back to 2014, inherited by Marriott International during its 2016 corporate acquisition.
Adversary Kill Chain Flow
5 Documented PhasesThreat actors deployed remote access trojans and memory scraping tools on Starwood guest reservation database servers prior to the acquisition.
Adversaries used Mimikatz to dump credentials from memory, gaining persistent domain administrator rights across the Starwood forest.
Operatives mapped the Starwood reservation database schema, locating tables housing guest profiles and passport identifiers.
Stolen guest records were exported, combined, and compressed into encrypted archives on local Starwood servers.
Archived customer records were systematically exfiltrated over encrypted channels to external command-and-control servers.
Unauthorized access to approximately 383 million guest records, including names, mailing addresses, phone numbers, passport numbers, travel details, and encrypted payment card numbers, resulting in a GBP 18.4M UK ICO GDPR fine and extensive global regulatory investigations.
Procedural & Incident Timeline
Starwood reservation system initially compromised prior to corporate acquisition by Marriott.
Internal security tool alerts on unauthorized database query attempting to download table records.
Marriott publicly discloses 383M customer record breach.
FTC announces formal final settlement requiring comprehensive information security program.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1078 | Valid Accounts Defense Evasion | "Operatives maintained administrative credentials within the Starwood network that survived the corporate acquisition of Starwood by Marriott International in 2016." | FTC Complaint: In re Marriott International, Inc. | reviewed |
| T1003 | OS Credential Dumping Credential Access | "Attackers utilized memory-scraping tools and credential harvesting scripts to pull plaintext payment card details before encryption at rest occurred." | UK Information Commissioner's Office Penalty Notice | reviewed |
| T1560 | "Adversaries created encrypted RAR archives of guest reservation records on local staging servers before exfiltrating them via hidden outbound channels." | SEC Form 8-K Marriott International | reviewed |