Marriott Starwood Data Breach (2014-18 Disclosed)
Introduction
On 30 November 2018, Marriott International disclosed that the guest reservation database of its Starwood Hotels subsidiary had been compromised — and that the intrusion had begun in 2014, two years before Marriott completed its acquisition of Starwood in September 2016. The exposed data included the records of up to 500 million guests as initially disclosed, later revised to approximately 339 million, covering passport numbers, encrypted payment card details, dates of birth, addresses, phone numbers, and travel history.
The breach is notable for three reasons: its scale, the duration of undetected access (at least four years), and the attribution of responsibility to a Chinese state-linked threat actor operating under the direction of the Ministry of State Security.
The Starwood Acquisition and Inherited Risk
Marriott agreed to acquire Starwood Hotels and Resorts Worldwide — operator of brands including Sheraton, Westin, W Hotels, St. Regis, and Le Méridien — in November 2015, completing the $13.6 billion acquisition in September 2016. The merged entity became the world's largest hotel company by number of rooms.
Due diligence during the acquisition process did not detect the intrusion already present in Starwood's reservation database. Critics and security researchers noted that cybersecurity due diligence in major acquisitions of this period was frequently inadequate relative to the depth of financial and operational scrutiny. Post-acquisition, Marriott did not promptly migrate Starwood's systems to its own infrastructure or conduct a thorough security assessment of the inherited database environment. The Starwood Reservation Database continued to operate as a separate system.
Discovery and the Scope of Exposure
The breach was discovered in September 2018 by Marriott's internal security tools, which flagged an attempt to access the Starwood guest reservation database. A forensic investigation determined that an unauthorised party had been present in the system since at least 2014 and had been exfiltrating data. The investigators found evidence that attackers had installed two pieces of malware — a Remote Access Trojan (RAT) and a tool used to copy and compress files for exfiltration.
The initial disclosure on 30 November 2018 placed the exposed records at up to 500 million. Subsequent forensic analysis revised the figure downward to approximately 339 million unique guest records. Of these, approximately 5.25 million unencrypted passport numbers and 20.3 million encrypted passport numbers were exposed; approximately 8.6 million encrypted payment card numbers were exposed, of which approximately 354,000 may still have been within expiry date at the time of disclosure.
Attribution: APT10 and Chinese State Intelligence
US and UK intelligence agencies, as well as independent security researchers, attributed the breach to APT10 — a threat actor also known as Stone Panda or MenuPass, assessed to be operating on behalf of China's Ministry of State Security (MSS). Reporting by the Washington Post and Reuters in late 2018, citing US officials, stated that intelligence agencies had concluded the attack was part of a broader Chinese intelligence-gathering operation targeting US citizens' travel, financial, and identification data.
The Chinese government denied involvement. The attribution was stated with confidence by US and UK officials but was not tested in a public legal proceeding in either jurisdiction.
UK GDPR Fine and Regulatory Response
Marriott notified the UK's Information Commissioner's Office within the 72-hour GDPR window. In July 2019, the ICO issued a Notice of Intent to fine Marriott £99.2 million under GDPR Article 83, citing failure to undertake sufficient due diligence in the Starwood acquisition and failure to implement adequate security measures. Seven million UK-resident records were among those exposed.
In October 2020, the ICO reduced the fine to £18.4 million, citing in part the economic impact of the COVID-19 pandemic on the hospitality sector and Marriott's cooperation with the investigation. The reduction was controversial; privacy advocates argued it undermined the deterrent effect of GDPR enforcement.
In the United States, the FTC investigated but did not impose a standalone fine. A class action settlement was reached separately; Marriott also faced regulatory scrutiny from multiple state attorneys general.
Verdict
Confirmed. The breach is documented through Marriott's own disclosures, ICO enforcement proceedings, congressional testimony, and forensic investigation records. The attribution to APT10 and Chinese MSS is assessed as credible by US and UK intelligence agencies. The failure of acquisition due diligence and post-acquisition security integration is confirmed by the ICO's findings.
The Record Count Kept Moving: 500 Million, Then 383 Million, Then 339 Million
One detail often flattened in retellings of this breach is that the headline number was never a single, stable figure. Marriott's initial 30 November 2018 disclosure said the Starwood database contained information on up to approximately 500 million guests. On 4 January 2019, Marriott issued an update revising that ceiling down to approximately 383 million — but the company was explicit that 383 million was an upper limit on the number of records, not a confirmed count of unique individuals, because many guests had multiple reservation records in the database. Marriott stated it believed the true number of unique guests affected was lower, but said it could not precisely quantify that smaller figure given the structure of the data. Later public reporting and regulatory summaries settled on approximately 339 million as the working figure for unique guest records, including roughly 5.25 million unencrypted passport numbers, 20.3 million encrypted passport numbers, and about 8.6 million encrypted payment card numbers (of which some 354,000 were still unexpired). Anyone citing a single fixed number for this breach is already simplifying a figure that shifted twice within two months of disclosure.
What "China Did It" Actually Rested On
The attribution to China's Ministry of State Security (MSS) is widely repeated, but it is worth being precise about what it was based on. In mid-December 2018, an unnamed US official briefed on the investigation told the Associated Press that investigators suspected hackers working for the MSS were responsible. FBI Assistant Director Bill Priestap, describing the broader pattern of Chinese intrusions being uncovered around the same period, told reporters: "Every rock we turn over, every time we looked for it, it's not only there, it's worse than we anticipated." That quote captured the mood of the investigation, but it was not a technical finding about Marriott specifically.
At the same time, independent cybersecurity researchers publicly pushed back on how solid the attribution was. Priscilla Moriuchi, then a threat-intelligence researcher at Recorded Future (and a former NSA analyst focused on East Asia), was quoted cautioning that "no one has put out any actual data or indicators showing Chinese state actor involvement in the Marriott intrusion." Reporting at the time also noted that the tools and techniques cited as evidence — while consistent with patterns seen in prior China-linked intrusions — were not unique to state actors and had in some cases been publicly available, meaning other actors could have used them too. Marriott itself, for its part, said at the time it had "no information about the cause of this incident" and had "not speculated about the identity of the attacker." None of this makes the China attribution false — US and UK intelligence agencies did converge on it, and it remains the dominant assessment — but the public evidentiary record supporting it is thinner than the confidence with which it is usually repeated.
The APT10 Indictment Didn't Name Marriott
It's a common point of confusion that the December 2018 US Department of Justice indictment of two Chinese nationals tied to APT10 (also referenced in the existing sources on this page) is sometimes read as "proof" the Marriott breach was legally established as Chinese state action. It wasn't. That indictment charged the defendants over the "Cloudhopper" campaign, which targeted managed service providers and their client networks — a related but legally distinct set of intrusions. No US or UK criminal charge, civil finding, or court judgment has ever named the Marriott/Starwood intrusion itself as a proven act of the Chinese state. The MSS attribution for Marriott specifically rests on intelligence-community assessment and officials' characterizations to journalists, not on a prosecuted case or a published forensic report naming Marriott.
A Second Reckoning: the FTC and 50-State Settlement of 2024
The regulatory story did not end with the ICO's 2020 fine. On 9 October 2024 — nearly six years after disclosure — the US Federal Trade Commission announced a settlement with Marriott and Starwood Hotels & Resorts Worldwide covering three separate data breaches spanning 2014 to 2020 that collectively compromised the personal data of more than 344 million consumers. The FTC itself imposed no monetary penalty, stating it lacked the statutory authority to seek one in this matter, but secured a 20-year consent order requiring biennial independent security assessments, annual risk assessments, a written information-security program built on data-minimization principles, vendor and franchisee oversight, security assessments during future acquisitions, and a route for US consumers to request deletion of their personal data and restoration of stolen loyalty points. Separately, on the same day, Marriott agreed to pay $52 million to settle with 49 state attorneys general and the District of Columbia, coordinated by Connecticut, Maryland, Oregon, Illinois, Louisiana, Massachusetts, North Carolina, Texas, and DC as co-leads. That settlement required Marriott to adopt zero-trust security architecture principles and enhanced employee training going forward. This is a materially different — and more consequential in dollar terms — regulatory outcome than the UK's £18.4 million ICO fine, and it postdates the original disclosure by six years, underscoring how long the legal tail of a breach of this scale runs.
2020: A Different Breach, Same Pattern
A detail frequently elided when people discuss "the Marriott breach" is that there was a second, entirely separate incident disclosed in 2020. On 31 March 2020, Marriott notified customers of unauthorized access to an application used by franchised and managed properties to service guests, which had compromised the records of approximately 5.2 million guests — contact details, loyalty account numbers, and personal preference data, though Marriott stated passwords, payment cards, and passport numbers were not involved. The intrusion is believed to have started around mid-January 2020, using the login credentials of two employees at a franchise property, and was discovered at the end of February 2020. This incident is legally and technically distinct from the 2014–2018 Starwood breach — different attack vector, different systems, no China attribution attached to it — but the FTC's 2024 settlement treats it as part of the same pattern of inadequate security oversight, particularly around franchisee and vendor access controls. Conflating the two breaches, or treating the 2020 incident as evidence of continued Starwood-era compromise, would be inaccurate; treating it as evidence Marriott's post-2018 security remediation was incomplete is what the regulators themselves concluded.
Delay Is Not the Same as Cover-Up
Because this page's verdict is "confirmed" — the breach indisputably happened and was disclosed — it's worth being precise about what remains genuinely disputed versus settled. The four-year gap between the 2014 intrusion and 2018 discovery is sometimes framed as suggesting Marriott (or Starwood before it) knew and sat on it. No regulatory finding — not the ICO's, not the FTC's — makes that claim. Both regulators' findings center on failure to detect and failure to adequately secure: inadequate due diligence during the 2016 acquisition, failure to encrypt or monitor the Starwood database sufficiently, and failure to migrate or fully audit inherited systems after the merger closed. That is a story of negligence and inadequate controls, not one of a documented decision to conceal a known breach. Marriott self-reported to the ICO within the GDPR's 72-hour window once it discovered the intrusion in September 2018, and disclosed publicly within roughly ten weeks of discovery. The distinction matters: "disclosed late because no one found it" and "disclosed late because it was hidden" carry very different implications, and the public record supports the former, not the latter.
What This Means for the Verdict
None of the above changes the verdict on this page. The breach happened, it was disclosed, the scale was enormous, and regulators on both sides of the Atlantic have now formally sanctioned Marriott over it — twice, six years apart. What the fuller record adds is calibration: the guest-record figure was a moving target rather than a single fixed number; the China attribution is a confident intelligence assessment repeated by officials and outlets, not a court-tested finding, and independent researchers have publicly noted the absence of published forensic proof; and the multi-year delay in detection reflects documented security and due-diligence failures rather than any established intent to conceal. A second, unrelated 2020 breach and a 2024 US regulatory settlement extend the story well past the original 2018 disclosure and show the security failures were not confined to the inherited Starwood system alone.
Evidence Filters17
Intrusion began 2014 — two years before Marriott acquisition closed
SupportingStrongForensic investigation determined attackers had been present in Starwood's reservation database since at least 2014. Marriott completed the Starwood acquisition in September 2016. The intrusion persisted for over four years in total before discovery.
339M guest records exposed including passport numbers
SupportingStrongApproximately 339 million unique guest records were exposed, including approximately 5.25 million unencrypted passport numbers, 20.3 million encrypted passport numbers, encrypted payment card details, travel itineraries, and personal contact information.
APT10 / China MSS attribution per US and UK intelligence
SupportingStrongUS and UK intelligence agencies attributed the breach to APT10 (Stone Panda), a threat actor assessed to be operating under the direction of China's Ministry of State Security. The Washington Post and Reuters reported the attribution citing US officials. The Chinese government denied involvement.
Rebuttal
Intelligence attribution to a state actor has not been tested in a public legal proceeding in either the US or UK. China's denial is expected and not inherently exculpatory. The attribution is assessed as credible by independent security researchers based on tools, infrastructure, and tradecraft.
Acquisition due diligence did not detect the intrusion
SupportingStrongMarriott's $13.6 billion acquisition of Starwood in 2015-16 did not include cybersecurity due diligence sufficient to detect an ongoing intrusion. Critics and the ICO noted this as a systemic failure of corporate acquisition practice in the technology sector.
ICO GDPR fine £99.2M reduced to £18.4M
SupportingStrongThe UK's Information Commissioner's Office issued an initial fine of £99.2 million in July 2019 under GDPR Article 83. Following representations from Marriott — citing COVID-19's economic impact and the company's cooperation — the ICO reduced the fine to £18.4 million in October 2020.
Starwood systems not migrated or fully assessed post-acquisition
SupportingStrongAfter completing the Starwood acquisition, Marriott did not promptly migrate Starwood's reservation systems to its own infrastructure. The Starwood Reservation Database continued to operate as a separate legacy system, deferring the security review that would have been required in a migration.
GDPR fine reduction criticised by privacy advocates
NeutralPrivacy advocates and data protection specialists criticised the ICO's reduction of the fine from £99.2M to £18.4M, arguing it weakened the deterrent effect of GDPR enforcement and sent a poor signal about accountability for large-scale breaches involving acquisition due-diligence failures.
Rebuttal
The ICO cited COVID-19 economic hardship and Marriott's cooperation as grounds for the reduction. Critics argued these factors should not apply to a pre-COVID security failure. The fine reduction is a legitimate policy disagreement, not evidence that the breach itself did not occur.
Breach disclosed within 72-hour GDPR window
NeutralWeakMarriott notified the ICO within the 72-hour GDPR breach notification requirement. This compliance with notification rules was cited in the ICO's subsequent proceedings as a mitigating factor alongside Marriott's cooperation with the investigation.
FTC and 49 State AG Settlement (Oct 2024) Confirms Pattern of Security Failures Across Three Separate Breaches
SupportingStrongOn 9 October 2024, the FTC and 49 state attorneys general plus DC announced settlements with Marriott covering three data breaches (2014-2020) collectively affecting more than 344 million consumers. The FTC secured a 20-year consent order requiring biennial independent security assessments; the states secured a $52 million payment. This is a second, later, and larger-dollar regulatory finding of security failure beyond the UK ICO's 2020 fine.
Separate 2020 Breach of 5.2 Million Guest Records Shows the Vulnerability Was Not a One-Off
SupportingOn 31 March 2020, Marriott disclosed a distinct, unrelated breach affecting roughly 5.2 million guest records, caused by compromised franchise-employee credentials accessing a guest-service application (intrusion believed to start mid-January 2020, discovered late February 2020). The FTC's 2024 settlement addresses this alongside the 2014-2018 Starwood breach as part of a recurring pattern of inadequate vendor/franchisee access controls.
Show 7 more evidence points
Guest Record Count Was Never Fixed: 500 Million to 383 Million (Upper Bound) to 339 Million
DebunkingMarriott's own 4 January 2019 update revised the initial 500 million estimate down to an upper limit of approximately 383 million records, explicitly stating this was not a confirmed unique-guest count due to duplicate records, and that the true unique-guest figure was believed lower but could not be precisely quantified. Later reporting and regulatory documents settled on ~339 million as the working figure.
Rebuttal
This is a limitation on precision, not a debunking of the breach itself — the breach's scale in the hundreds of millions is not in dispute, only the exact headline number, which Marriott itself said it could not pin down precisely.
No Criminal Indictment or Court Finding Has Ever Named the Marriott/Starwood Intrusion Specifically as Chinese State Action
DebunkingStrongThe December 2018 DOJ indictment of two individuals tied to APT10/Cloudhopper charged intrusions into managed service providers, not the Marriott/Starwood breach. No subsequent US or UK criminal case, civil judgment, or published forensic report has formally named the Marriott intrusion as a proven act of the Chinese state; the MSS attribution rests on intelligence-community assessment relayed to journalists, not a prosecuted or adjudicated case.
Rebuttal
US and UK intelligence agencies did converge on the China/MSS assessment, and it remains the dominant official view — the absence of a criminal case reflects the nature of state-attribution intelligence (rarely tested in open court), not evidence the assessment is wrong.
Independent Threat Researchers Publicly Disputed the Strength of the China Attribution
DebunkingPriscilla Moriuchi, then a threat-intelligence researcher at Recorded Future and former NSA East Asia analyst, was quoted in December 2018 stating 'no one has put out any actual data or indicators showing Chinese state actor involvement in the Marriott intrusion.' Marriott itself said at the time it had 'no information about the cause of this incident' and had not speculated about the attacker's identity.
Rebuttal
Attribution intelligence is frequently withheld from public release to protect sources and methods, so the absence of published technical indicators does not by itself invalidate the officials' assessment — it means the public record cannot independently verify it.
Regulatory Findings Establish Security-Control Failures, Not Deliberate Concealment
DebunkingStrongBoth the UK ICO's penalty notices and the 2024 FTC/state settlement ground their findings in inadequate acquisition due diligence, insufficient encryption/monitoring, and failure to integrate or audit the inherited Starwood systems — not in any finding that Marriott or Starwood knew of and hid a breach. Marriott self-reported to the ICO within the GDPR's 72-hour window after discovering the intrusion in September 2018 and disclosed publicly within about ten weeks.
ICO's Own Fine Was Cut by Over 80% Using Discretionary Mitigating Factors, Including COVID-19 Hardship
DebunkingThe ICO reduced its proposed £99.2 million fine to £18.4 million, citing mitigating factors including Marriott's cooperation and the economic impact of the COVID-19 pandemic on the hospitality sector at the time of the final decision (October 2020) — factors unrelated to the underlying severity of the security failures found.
Rebuttal
A discretionary reduction in penalty amount does not change the ICO's underlying findings of fact about inadequate security; it reflects regulatory discretion in sentencing-equivalent terms, not a retraction of the findings.
Acquisition Due-Diligence Gap Was a Known M&A Risk, Not Deliberate Concealment
NeutralCyber-security due diligence in major corporate acquisitions was not standardized practice in 2015-2016 when Marriott acquired Starwood. The gap was a known industry problem — acquirers routinely inherited legacy security vulnerabilities without discovering them pre-close. Post-Marriott, M&A cybersecurity diligence became a standard practice area. This trajectory — problem identified, industry practice changes — is consistent with systemic learning, not with evidence that Marriott knew of the breach during acquisition and concealed it.
APT10 Attribution Reflects Industry-Wide Intelligence Consensus, Not Unverifiable Conspiracy Claim
DebunkingThe attribution of the Marriott Starwood breach to APT10 (Stone Panda), a Chinese state-sponsored threat actor, reflects consensus findings from Marriott's forensic investigators (FireEye/Mandiant), UK NCSC, and US IC community assessments. The UK ICO's finding of inadequate security — resulting in a fine — and the subsequent US DOJ indictment of APT10 members for related campaigns both occurred through transparent legal and regulatory processes. The breach's state-actor attribution is one of the more robustly documented in commercial cyber-espionage history.
Evidence Cited by Believers8
Intrusion began 2014 — two years before Marriott acquisition closed
SupportingStrongForensic investigation determined attackers had been present in Starwood's reservation database since at least 2014. Marriott completed the Starwood acquisition in September 2016. The intrusion persisted for over four years in total before discovery.
339M guest records exposed including passport numbers
SupportingStrongApproximately 339 million unique guest records were exposed, including approximately 5.25 million unencrypted passport numbers, 20.3 million encrypted passport numbers, encrypted payment card details, travel itineraries, and personal contact information.
APT10 / China MSS attribution per US and UK intelligence
SupportingStrongUS and UK intelligence agencies attributed the breach to APT10 (Stone Panda), a threat actor assessed to be operating under the direction of China's Ministry of State Security. The Washington Post and Reuters reported the attribution citing US officials. The Chinese government denied involvement.
Rebuttal
Intelligence attribution to a state actor has not been tested in a public legal proceeding in either the US or UK. China's denial is expected and not inherently exculpatory. The attribution is assessed as credible by independent security researchers based on tools, infrastructure, and tradecraft.
Acquisition due diligence did not detect the intrusion
SupportingStrongMarriott's $13.6 billion acquisition of Starwood in 2015-16 did not include cybersecurity due diligence sufficient to detect an ongoing intrusion. Critics and the ICO noted this as a systemic failure of corporate acquisition practice in the technology sector.
ICO GDPR fine £99.2M reduced to £18.4M
SupportingStrongThe UK's Information Commissioner's Office issued an initial fine of £99.2 million in July 2019 under GDPR Article 83. Following representations from Marriott — citing COVID-19's economic impact and the company's cooperation — the ICO reduced the fine to £18.4 million in October 2020.
Starwood systems not migrated or fully assessed post-acquisition
SupportingStrongAfter completing the Starwood acquisition, Marriott did not promptly migrate Starwood's reservation systems to its own infrastructure. The Starwood Reservation Database continued to operate as a separate legacy system, deferring the security review that would have been required in a migration.
FTC and 49 State AG Settlement (Oct 2024) Confirms Pattern of Security Failures Across Three Separate Breaches
SupportingStrongOn 9 October 2024, the FTC and 49 state attorneys general plus DC announced settlements with Marriott covering three data breaches (2014-2020) collectively affecting more than 344 million consumers. The FTC secured a 20-year consent order requiring biennial independent security assessments; the states secured a $52 million payment. This is a second, later, and larger-dollar regulatory finding of security failure beyond the UK ICO's 2020 fine.
Separate 2020 Breach of 5.2 Million Guest Records Shows the Vulnerability Was Not a One-Off
SupportingOn 31 March 2020, Marriott disclosed a distinct, unrelated breach affecting roughly 5.2 million guest records, caused by compromised franchise-employee credentials accessing a guest-service application (intrusion believed to start mid-January 2020, discovered late February 2020). The FTC's 2024 settlement addresses this alongside the 2014-2018 Starwood breach as part of a recurring pattern of inadequate vendor/franchisee access controls.
Counter-Evidence6
Guest Record Count Was Never Fixed: 500 Million to 383 Million (Upper Bound) to 339 Million
DebunkingMarriott's own 4 January 2019 update revised the initial 500 million estimate down to an upper limit of approximately 383 million records, explicitly stating this was not a confirmed unique-guest count due to duplicate records, and that the true unique-guest figure was believed lower but could not be precisely quantified. Later reporting and regulatory documents settled on ~339 million as the working figure.
Rebuttal
This is a limitation on precision, not a debunking of the breach itself — the breach's scale in the hundreds of millions is not in dispute, only the exact headline number, which Marriott itself said it could not pin down precisely.
No Criminal Indictment or Court Finding Has Ever Named the Marriott/Starwood Intrusion Specifically as Chinese State Action
DebunkingStrongThe December 2018 DOJ indictment of two individuals tied to APT10/Cloudhopper charged intrusions into managed service providers, not the Marriott/Starwood breach. No subsequent US or UK criminal case, civil judgment, or published forensic report has formally named the Marriott intrusion as a proven act of the Chinese state; the MSS attribution rests on intelligence-community assessment relayed to journalists, not a prosecuted or adjudicated case.
Rebuttal
US and UK intelligence agencies did converge on the China/MSS assessment, and it remains the dominant official view — the absence of a criminal case reflects the nature of state-attribution intelligence (rarely tested in open court), not evidence the assessment is wrong.
Independent Threat Researchers Publicly Disputed the Strength of the China Attribution
DebunkingPriscilla Moriuchi, then a threat-intelligence researcher at Recorded Future and former NSA East Asia analyst, was quoted in December 2018 stating 'no one has put out any actual data or indicators showing Chinese state actor involvement in the Marriott intrusion.' Marriott itself said at the time it had 'no information about the cause of this incident' and had not speculated about the attacker's identity.
Rebuttal
Attribution intelligence is frequently withheld from public release to protect sources and methods, so the absence of published technical indicators does not by itself invalidate the officials' assessment — it means the public record cannot independently verify it.
Regulatory Findings Establish Security-Control Failures, Not Deliberate Concealment
DebunkingStrongBoth the UK ICO's penalty notices and the 2024 FTC/state settlement ground their findings in inadequate acquisition due diligence, insufficient encryption/monitoring, and failure to integrate or audit the inherited Starwood systems — not in any finding that Marriott or Starwood knew of and hid a breach. Marriott self-reported to the ICO within the GDPR's 72-hour window after discovering the intrusion in September 2018 and disclosed publicly within about ten weeks.
ICO's Own Fine Was Cut by Over 80% Using Discretionary Mitigating Factors, Including COVID-19 Hardship
DebunkingThe ICO reduced its proposed £99.2 million fine to £18.4 million, citing mitigating factors including Marriott's cooperation and the economic impact of the COVID-19 pandemic on the hospitality sector at the time of the final decision (October 2020) — factors unrelated to the underlying severity of the security failures found.
Rebuttal
A discretionary reduction in penalty amount does not change the ICO's underlying findings of fact about inadequate security; it reflects regulatory discretion in sentencing-equivalent terms, not a retraction of the findings.
APT10 Attribution Reflects Industry-Wide Intelligence Consensus, Not Unverifiable Conspiracy Claim
DebunkingThe attribution of the Marriott Starwood breach to APT10 (Stone Panda), a Chinese state-sponsored threat actor, reflects consensus findings from Marriott's forensic investigators (FireEye/Mandiant), UK NCSC, and US IC community assessments. The UK ICO's finding of inadequate security — resulting in a fine — and the subsequent US DOJ indictment of APT10 members for related campaigns both occurred through transparent legal and regulatory processes. The breach's state-actor attribution is one of the more robustly documented in commercial cyber-espionage history.
Neutral / Ambiguous3
GDPR fine reduction criticised by privacy advocates
NeutralPrivacy advocates and data protection specialists criticised the ICO's reduction of the fine from £99.2M to £18.4M, arguing it weakened the deterrent effect of GDPR enforcement and sent a poor signal about accountability for large-scale breaches involving acquisition due-diligence failures.
Rebuttal
The ICO cited COVID-19 economic hardship and Marriott's cooperation as grounds for the reduction. Critics argued these factors should not apply to a pre-COVID security failure. The fine reduction is a legitimate policy disagreement, not evidence that the breach itself did not occur.
Breach disclosed within 72-hour GDPR window
NeutralWeakMarriott notified the ICO within the 72-hour GDPR breach notification requirement. This compliance with notification rules was cited in the ICO's subsequent proceedings as a mitigating factor alongside Marriott's cooperation with the investigation.
Acquisition Due-Diligence Gap Was a Known M&A Risk, Not Deliberate Concealment
NeutralCyber-security due diligence in major corporate acquisitions was not standardized practice in 2015-2016 when Marriott acquired Starwood. The gap was a known industry problem — acquirers routinely inherited legacy security vulnerabilities without discovering them pre-close. Post-Marriott, M&A cybersecurity diligence became a standard practice area. This trajectory — problem identified, industry practice changes — is consistent with systemic learning, not with evidence that Marriott knew of the breach during acquisition and concealed it.
Timeline
Starwood reservation database first compromised
Forensic investigation later determines that attackers — attributed to APT10, assessed to operate under Chinese MSS direction — first gained access to the Starwood guest reservation database. The intrusion goes undetected. Exfiltration of passport numbers, payment cards, and travel history data begins.
Marriott acquisition of Starwood closes; intrusion not discovered
Marriott International completes its $13.6 billion acquisition of Starwood Hotels and Resorts, creating the world's largest hotel company. Due diligence does not detect the ongoing intrusion in the Starwood Reservation Database. The system continues to operate as a separate legacy environment post-acquisition.
Breach disclosed — 339M records exposed, intrusion since 2014
Marriott discloses the Starwood breach publicly on 30 November 2018, within the 72-hour GDPR window. Initial figure of up to 500 million records is later revised to approximately 339 million. US and UK intelligence attribute the attack to APT10 and Chinese MSS. The breach had persisted for over four years.
Source →US officials point to China's Ministry of State Security, but researchers question the evidence
An unnamed US official briefed on the investigation told the Associated Press that hackers working for China's Ministry of State Security were suspected in the breach. The same reporting cited independent researcher Priscilla Moriuchi of Recorded Future cautioning that no public data or indicators had been released showing Chinese state involvement, and quoted Marriott saying it had not speculated about the attacker's identity.
Verdict
Starwood reservation database compromised since 2014. Marriott acquired Starwood Sep 2016 without detecting the intrusion. Breach disclosed 30 Nov 2018. ~339M guest records exposed including passport numbers and payment cards. APT10 (China MSS) attribution per US and UK intelligence. ICO GDPR fine £99.2M Jul 2019 reduced to £18.4M Oct 2020. 7M UK records affected.
Frequently Asked Questions
How was a breach that began in 2014 undetected for four years?
The intrusion occurred in Starwood's reservation database prior to the Marriott acquisition. Due diligence during the acquisition did not include cybersecurity assessment sufficient to detect the ongoing intrusion. Post-acquisition, Marriott did not promptly migrate Starwood systems to its own infrastructure. The attacker used legitimate-looking remote access tools and staged data for exfiltration in ways designed to avoid triggering standard alerts.
Was the Marriott breach really carried out by China?
US and UK intelligence agencies attributed the breach to APT10, assessed to operate under China's Ministry of State Security direction, based on tools, infrastructure, and tradecraft analysis. Independent security researchers concurred. The DOJ indicted two APT10 members in December 2018. China denied involvement. The attribution has not been tested in a public legal proceeding but is considered credible by the intelligence and security research community.
Why was the GDPR fine reduced so significantly?
The ICO reduced the fine from £99.2M to £18.4M citing the economic impact of COVID-19 on the hospitality sector and Marriott's cooperation with the investigation. Privacy advocates criticised the reduction, arguing it undermined GDPR deterrence and rewarded cooperation in a way that was disproportionate to the scale of the breach and the due-diligence failure during the acquisition.
Was China ever criminally charged or legally proven responsible for the Marriott/Starwood breach specifically?
Sources
Show 10 more sources
Further Reading
- paperAPT10 indictment — DOJ press release — US Department of Justice (2018)
- articleChina suspected in huge Marriott data breach, official says — PBS NewsHour (2018)
- bookSandworm: A New Era of Cyberwar and the Hunt for the Kremlin's Most Dangerous Hackers — Andy Greenberg (2019)
- paperICO Marriott International enforcement notice — full decision — Information Commissioner's Office (2020)
- articleMarriott Data Breach: How 383M Guest Records Were Exposed — Breachsense
- articleCompromise of Marriott International — Council on Foreign Relations