Marriott and Starwood (2018): A Breach Inherited Through an Acquisition
Summary
In November 2018, Marriott International disclosed unauthorised access to the Starwood guest reservation database. Investigation established that unauthorised access dated back to 2014. Marriott completed its acquisition of Starwood in 2016, meaning the compromise predated the acquisition by roughly two years and continued undetected for a further two years afterward. The UK Information Commissioner's Office subsequently issued a fine under GDPR.
Technical Root Cause
The public record is less specific on the initial vector than for many incidents on this list, and it is worth being honest about that rather than filling the gap. What is well established is the timeline: an intrusion beginning in 2014, persisting through a corporate acquisition, and remaining undetected until an internal security tool flagged an anomalous database query in September 2018. Reported exposure included names, contact details, passport numbers and, for some records, encrypted payment card data.
Why It Mattered
Two features make this case distinctive.
The first is dwell time. Four years of undetected access is long even by the standards of large breaches, and it demonstrates that detection capability, not prevention alone, determines how much a given intrusion ultimately costs.
The second is the acquisition. Marriott acquired the liability along with the company, and the compromise was already active during the due diligence period. Security due diligence in mergers and acquisitions was, at the time, frequently limited to policy review and questionnaires rather than technical assessment, which would not have surfaced an active intruder.
OWASP / CWE Mapping
- OWASP A09:2021: Security Logging and Monitoring Failures (the defining failure here)
- OWASP A02:2021: Cryptographic Failures (regarding what protection applied to which fields)
Lasting Impact
Marriott is the standard reference for technical security due diligence as a required element of M&A rather than an optional one, including compromise assessment of the target's environment before integration. It also reinforced that integrating an acquired company's systems extends the acquirer's attack surface to include everything the target failed to detect.
How Safeguard Helps
M&A acquirers are an explicit audience for supply chain and software inventory assessment: establishing what an acquired estate actually contains, and what known-vulnerable components it carries, is a concrete and verifiable part of technical due diligence.
References
- ICO penalty notice: https://ico.org.uk/action-weve-taken/enforcement/marriott-international-inc/