Safeguard
Vulnerability Analysis

Marriott and Starwood (2018): A Breach Inherited Through an Acquisition

A factual retrospective on the Marriott breach disclosed in 2018, where attackers had been present in the Starwood reservation system since 2014, two years before Marriott acquired the company.

Safeguard Research Team
2 min read

Marriott and Starwood (2018): A Breach Inherited Through an Acquisition

Summary

In November 2018, Marriott International disclosed unauthorised access to the Starwood guest reservation database. Investigation established that unauthorised access dated back to 2014. Marriott completed its acquisition of Starwood in 2016, meaning the compromise predated the acquisition by roughly two years and continued undetected for a further two years afterward. The UK Information Commissioner's Office subsequently issued a fine under GDPR.

Technical Root Cause

The public record is less specific on the initial vector than for many incidents on this list, and it is worth being honest about that rather than filling the gap. What is well established is the timeline: an intrusion beginning in 2014, persisting through a corporate acquisition, and remaining undetected until an internal security tool flagged an anomalous database query in September 2018. Reported exposure included names, contact details, passport numbers and, for some records, encrypted payment card data.

Why It Mattered

Two features make this case distinctive.

The first is dwell time. Four years of undetected access is long even by the standards of large breaches, and it demonstrates that detection capability, not prevention alone, determines how much a given intrusion ultimately costs.

The second is the acquisition. Marriott acquired the liability along with the company, and the compromise was already active during the due diligence period. Security due diligence in mergers and acquisitions was, at the time, frequently limited to policy review and questionnaires rather than technical assessment, which would not have surfaced an active intruder.

OWASP / CWE Mapping

  • OWASP A09:2021: Security Logging and Monitoring Failures (the defining failure here)
  • OWASP A02:2021: Cryptographic Failures (regarding what protection applied to which fields)

Lasting Impact

Marriott is the standard reference for technical security due diligence as a required element of M&A rather than an optional one, including compromise assessment of the target's environment before integration. It also reinforced that integrating an acquired company's systems extends the acquirer's attack surface to include everything the target failed to detect.

How Safeguard Helps

M&A acquirers are an explicit audience for supply chain and software inventory assessment: establishing what an acquired estate actually contains, and what known-vulnerable components it carries, is a concrete and verifiable part of technical due diligence.

References

Never miss an update

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.