CASE DOSSIER settled

Marriott Starwood 383 Million Guest Reservation Breach

Docket: FTC Docket No. C-4712 Court: U.S. District Court for the District of Maryland Opened: 2018-11-30 Sector: Hospitality & Travel

Key Facts

Status
SETTLED
Legal disposition
Loss Amount
$250.0 million
$123M ICO GDPR fine, $52M multi-state AG settlement, and FTC administrative consent order.
Techniques
3
Verified mappings
Defendants
0
Named in charges
  • Legal Status: SETTLED in U.S. District Court for the District of Maryland.
  • Primary Target Sector: Hospitality & Travel.
  • Documented Financial Loss: $250.0 million.
  • 3 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

State-sponsored cyber espionage operators maintained undetected access to the Starwood guest reservation database for four years, deploying remote access trojans and memory scrapers to exfiltrate unencrypted passport numbers, payment cards, and travel itineraries.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Undetected legacy compromise of the Starwood Hotels & Resorts guest reservation database network dating back to 2014, inherited by Marriott International during its 2016 corporate acquisition.

Operational & Financial Fallout

Unauthorized access to approximately 383 million guest records, including names, mailing addresses, phone numbers, passport numbers, travel details, and encrypted payment card numbers, resulting in a GBP 18.4M UK ICO GDPR fine and extensive global regulatory investigations.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: SETTLED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Undetected legacy compromise of the Starwood Hotels & Resorts guest reservation database network dating back to 2014, inherited by Marriott International during its 2016 corporate acquisition.

Adversary Kill Chain Flow

5 Documented Phases
1
Initial Access Legacy Network Compromise
MITRE ATT&CK T1190 →

Threat actors deployed remote access trojans and memory scraping tools on Starwood guest reservation database servers prior to the acquisition.

Artifacts & Tooling: Remote access trojan Legacy backdoors
2
Privilege Escalation Credential Harvesting & Admin Takeover
MITRE ATT&CK T1003 →

Adversaries used Mimikatz to dump credentials from memory, gaining persistent domain administrator rights across the Starwood forest.

Artifacts & Tooling: Mimikatz credential dump Active Directory domain admin compromise
3
Discovery Internal Database Reconnaissance
MITRE ATT&CK T1087 →

Operatives mapped the Starwood reservation database schema, locating tables housing guest profiles and passport identifiers.

Artifacts & Tooling: Reservation schema enumeration Database query scripts
4
Collection Encrypted File Staging
MITRE ATT&CK T1074.001 →

Stolen guest records were exported, combined, and compressed into encrypted archives on local Starwood servers.

Artifacts & Tooling: Encrypted RAR/7z archives Staged database dumps
5
Exfiltration Exfiltration to Remote Command Servers
MITRE ATT&CK T1048 →

Archived customer records were systematically exfiltrated over encrypted channels to external command-and-control servers.

Artifacts & Tooling: Encrypted C2 outbound transfer External drop servers
Real-World Blast Radius & Operational Fallout

Unauthorized access to approximately 383 million guest records, including names, mailing addresses, phone numbers, passport numbers, travel details, and encrypted payment card numbers, resulting in a GBP 18.4M UK ICO GDPR fine and extensive global regulatory investigations.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Perform comprehensive cybersecurity due diligence and compromise assessments on acquiree IT networks prior to merger completion.
✓ Segment and isolate acquired legacy networks from corporate parent directories until independent audits confirm clean status.
✓ Deploy endpoint detection and response (EDR) across all servers, including legacy database hosts.
✓ Store sensitive identity data such as passport numbers in encrypted, tokenized data repositories.

Procedural & Incident Timeline

2014-07-01 incident

Starwood reservation system initially compromised prior to corporate acquisition by Marriott.

2018-09-08 discovery

Internal security tool alerts on unauthorized database query attempting to download table records.

2018-11-30 disclosure

Marriott publicly discloses 383M customer record breach.

2024-10-08 settlement

FTC announces formal final settlement requiring comprehensive information security program.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1078 Valid Accounts
Defense Evasion
"Operatives maintained administrative credentials within the Starwood network that survived the corporate acquisition of Starwood by Marriott International in 2016." FTC Complaint: In re Marriott International, Inc. reviewed
T1003 OS Credential Dumping
Credential Access
"Attackers utilized memory-scraping tools and credential harvesting scripts to pull plaintext payment card details before encryption at rest occurred." UK Information Commissioner's Office Penalty Notice reviewed
T1560
"Adversaries created encrypted RAR archives of guest reservation records on local staging servers before exfiltrating them via hidden outbound channels." SEC Form 8-K Marriott International reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, Marriott Starwood 383 Million Guest Reservation Breach, No. FTC Docket No. C-4712 (U.S. District Court for the District of Maryland 2018), https://cybercaselibrary.com/cases/marriott-starwood-guest-reservation-breach/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/marriott-starwood-guest-reservation-breach" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>