Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Marriott disclosed unauthorized access to the Starwood guest reservation database on November 30, 2018. The company initially estimated that records for up to approximately 500 million guests might be involved, but later said fewer than 383 million unique guests were affected. The incident involved Starwood reservation data—not every Marriott system—and the information varied from record to record.

What happened in the Marriott-Starwood breach?

Marriott said its investigation had determined on November 19, 2018, that someone had accessed the Starwood guest reservation database without authorization. The company publicly disclosed the incident on November 30. Its notice concerned reservations at Starwood properties on or before September 10, 2018. Marriott’s original announcement describes the discovery and the systems involved.

The dates describe different parts of the account: September 10 was the reservation cutoff in Marriott’s notice, November 19 was when Marriott said its investigation determined unauthorized access, and November 30 was the public announcement. A later Federal Trade Commission complaint alleged attackers had been in the network for years; that is an allegation in the complaint, not a date established by Marriott’s initial public notice. The FTC complaint sets out the regulator’s allegations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How many guests or records were involved?

The commonly repeated 500 million figure was Marriott’s initial estimate of potentially affected guests. It was not a verified count of unique people: the estimate came before duplicate records were removed. Marriott’s later annual report said fewer than 383 million unique guests were involved, while noting it could not quantify that lower number precisely. Marriott’s 2019 annual report provides the later company estimate.

Date and source Reported figure What it counts
2018, Marriott’s initial announcement Up to approximately 500 million Potentially affected guests, before duplicate-record analysis; an initial estimate.
2019, Marriott’s annual report Fewer than 383 million Unique guests, according to Marriott; the company said it could not quantify the lower number precisely.
2024, FTC complaint 339 million Consumer records described in the complaint; this is not a reconciled count of unique people.

These figures use different units and come from different documents. In particular, the FTC’s 339 million figure is a count of records in its complaint, not a final determination that 339 million distinct individuals were affected. The complaint is a regulator’s allegations document.

What information may have been exposed?

Marriott said affected reservation records could contain different combinations of information. Its notice listed names, mailing addresses, phone numbers, email addresses, passport numbers, Starwood Preferred Guest account information, dates of birth, gender, arrival and departure information, reservation dates, and communication preferences. It did not say that every affected record contained every listed field. The original notice describes the possible data categories.

For some records, payment-card numbers and expiration dates might also have been involved. Marriott said the card numbers were encrypted but that it could not rule out access to the encryption key. That statement does not establish that payment-card data was exposed for every guest—or that the encryption key was accessed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How did Marriott notify guests?

Marriott said it notified guests by email on a rolling basis, completing the emails on December 21, 2018. It also reported that it contacted law enforcement and set up a dedicated incident website and call center. These are Marriott’s reported response steps; they do not establish that every guest saw a notice, and the historical enrollment offer should not be assumed to remain available. Marriott’s annual report gives the email completion date.

What should a potentially affected guest do?

The disclosure concerns historical reservation data. If you are concerned, use Marriott’s official website or account channels to check relevant communications and account details. Be cautious with unsolicited messages that refer to a hotel stay, destination, or travel dates: information drawn from a reservation can make a fraudulent message seem credible.

  • Do not share passwords, account verification codes, or payment details in response to an unexpected call, email, or text.
  • Reach Marriott through contact details you find independently on its official site rather than through links or numbers in a suspicious message.
  • Keep sensitive account information out of public comments or posts.

The available incident documents do not support a claim that buying a particular product can reverse the exposure or guarantee protection.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What regulatory action followed?

The regulatory record includes separate actions in the United Kingdom and United States. A complaint, a final penalty decision, and a later settlement announcement are different legal steps; they should not be treated as interchangeable findings.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Jurisdiction and date Action What it means
United Kingdom, October 2020 The Information Commissioner’s Office imposed an £18.4 million penalty. A final ICO penalty decision. Marriott said the decision ended the UK and EU regulatory investigation and concerned the separate Starwood network, which was no longer in use.
United States, FTC complaint The FTC filed a complaint alleging security failures and describing 339 million consumer records. Allegations in a regulator’s complaint; not a count of unique people established after trial.
United States, October 2024 Marriott announced resolutions of FTC and state attorneys general investigations. It said the state resolution included a $52 million payment and security commitments. A resolution announcement by Marriott, distinct from the allegations in the FTC complaint and the ICO’s final penalty.

The ICO’s notice records the UK penalty. Read the ICO’s October 2020 announcement. Marriott described the later U.S. outcome in its October 2024 announcement.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.