{
  "id": "case-marriott-starwood",
  "slug": "marriott-starwood-guest-reservation-breach",
  "title": "Marriott Starwood 383 Million Guest Reservation Breach",
  "summary": "State-sponsored cyber espionage operators maintained undetected access to the Starwood guest reservation database for four years, deploying remote access trojans and memory scrapers to exfiltrate unencrypted passport numbers, payment cards, and travel itineraries.",
  "case_number": "FTC Docket No. C-4712",
  "court": "U.S. District Court for the District of Maryland",
  "district": "D. Md.",
  "country": "United States",
  "opened_at": "2018-11-30",
  "status": "settled",
  "victim_sector": "Hospitality & Travel",
  "victim_country": "United States",
  "loss_amount_usd": 250000000,
  "loss_amount_note": "$123M ICO GDPR fine, $52M multi-state AG settlement, and FTC administrative consent order.",
  "first_seen_at": "2014-07-01T00:00:00Z",
  "last_updated_at": "2026-10-02T10:00:00Z",
  "actor_slug": "apt41",
  "defendant_slugs": [],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1078",
      "evidence_excerpt": "Operatives maintained administrative credentials within the Starwood network that survived the corporate acquisition of Starwood by Marriott International in 2016.",
      "evidence_locator": "FTC Complaint: In re Marriott International, Inc.",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "FTC Decision & Order: Marriott International",
      "source_url": "https://www.ftc.gov",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1003",
      "evidence_excerpt": "Attackers utilized memory-scraping tools and credential harvesting scripts to pull plaintext payment card details before encryption at rest occurred.",
      "evidence_locator": "UK Information Commissioner's Office Penalty Notice",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "ICO Penalty Notice: Marriott International Inc",
      "source_url": "https://ico.org.uk",
      "technique_name": "OS Credential Dumping",
      "tactic": "Credential Access"
    },
    {
      "technique_id": "T1560",
      "evidence_excerpt": "Adversaries created encrypted RAR archives of guest reservation records on local staging servers before exfiltrating them via hidden outbound channels.",
      "evidence_locator": "SEC Form 8-K Marriott International",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "SEC Form 8-K Marriott",
      "source_url": "https://www.sec.gov"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2014-07-01",
      "description": "Starwood reservation system initially compromised prior to corporate acquisition by Marriott."
    },
    {
      "event_type": "discovery",
      "event_date": "2018-09-08",
      "description": "Internal security tool alerts on unauthorized database query attempting to download table records."
    },
    {
      "event_type": "disclosure",
      "event_date": "2018-11-30",
      "description": "Marriott publicly discloses 383M customer record breach."
    },
    {
      "event_type": "settlement",
      "event_date": "2024-10-08",
      "description": "FTC announces formal final settlement requiring comprehensive information security program."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Undetected legacy compromise of the Starwood Hotels & Resorts guest reservation database network dating back to 2014, inherited by Marriott International during its 2016 corporate acquisition.",
    "blast_radius": "Unauthorized access to approximately 383 million guest records, including names, mailing addresses, phone numbers, passport numbers, travel details, and encrypted payment card numbers, resulting in a GBP 18.4M UK ICO GDPR fine and extensive global regulatory investigations.",
    "kill_chain": [
      {
        "phase": "Initial Access",
        "title": "Legacy Network Compromise",
        "description": "Threat actors deployed remote access trojans and memory scraping tools on Starwood guest reservation database servers prior to the acquisition.",
        "technical_artifacts": [
          "Remote access trojan",
          "Legacy backdoors"
        ],
        "mitre_technique_id": "T1190"
      },
      {
        "phase": "Privilege Escalation",
        "title": "Credential Harvesting & Admin Takeover",
        "description": "Adversaries used Mimikatz to dump credentials from memory, gaining persistent domain administrator rights across the Starwood forest.",
        "technical_artifacts": [
          "Mimikatz credential dump",
          "Active Directory domain admin compromise"
        ],
        "mitre_technique_id": "T1003"
      },
      {
        "phase": "Discovery",
        "title": "Internal Database Reconnaissance",
        "description": "Operatives mapped the Starwood reservation database schema, locating tables housing guest profiles and passport identifiers.",
        "technical_artifacts": [
          "Reservation schema enumeration",
          "Database query scripts"
        ],
        "mitre_technique_id": "T1087"
      },
      {
        "phase": "Collection",
        "title": "Encrypted File Staging",
        "description": "Stolen guest records were exported, combined, and compressed into encrypted archives on local Starwood servers.",
        "technical_artifacts": [
          "Encrypted RAR/7z archives",
          "Staged database dumps"
        ],
        "mitre_technique_id": "T1074.001"
      },
      {
        "phase": "Exfiltration",
        "title": "Exfiltration to Remote Command Servers",
        "description": "Archived customer records were systematically exfiltrated over encrypted channels to external command-and-control servers.",
        "technical_artifacts": [
          "Encrypted C2 outbound transfer",
          "External drop servers"
        ],
        "mitre_technique_id": "T1048"
      }
    ],
    "defensive_takeaways": [
      "Perform comprehensive cybersecurity due diligence and compromise assessments on acquiree IT networks prior to merger completion.",
      "Segment and isolate acquired legacy networks from corporate parent directories until independent audits confirm clean status.",
      "Deploy endpoint detection and response (EDR) across all servers, including legacy database hosts.",
      "Store sensitive identity data such as passport numbers in encrypted, tokenized data repositories."
    ]
  }
}