Skip to main content

Fact check

Is it true: Marriott Starwood data breach (2014-18 disclosed)?

Confirmed4% confidence

Yes — this is confirmed.

Starwood reservation database compromised since 2014. Marriott acquired Starwood Sep 2016 without detecting the intrusion. Breach disclosed 30 Nov 2018. ~339M guest records exposed including passport numbers and payment cards. APT10 (China MSS) attribution per US and UK intelligence. ICO GDPR fine £99.2M Jul 2019 reduced to £18.4M Oct 2020. 7M UK records affected.

The claim

The Marriott Starwood breach exposed approximately 339 million guest records — including passport numbers, encrypted payment card details, and travel history — from a database that had been compromise

Key evidence

Intrusion began 2014 — two years before Marriott acquisition closed

APT10 Attribution Reflects Industry-Wide Intelligence Consensus, Not Unverifiable Conspiracy Claim

Read the full evidence file

Conspirafy steelmans each claim, then follows the evidence. How we reach a verdict · Check another claim