First reportedNovember 30, 2018
ActivityActivity date not specified
Last updatedFeb 2, 2026, 12:00 AM UTC
Record confidencemed

Key facts

Affected

  • Marriott/Starwood guests
  • Marriott International, Inc.

Initial access

  • unknown

Impact

  • data_theft
  • financial_loss

Attribution

unknown low confidence

Cited sources focus on breach disclosure and regulatory outcomes; definitive public attribution is not provided in the included materials.

CVEs and ATT&CK

No CVE or ATT&CK association is captured in this curated record.

Mitigations

Now

  • Encrypt and segment reservation databases and restrict administrative accessLimits exposure of large customer datasets and reduces the scope of compromise.

Soon

  • Implement continuous monitoring for privileged access to customer databasesImproves detection of unusual administrative activity and bulk reads of sensitive tables.

Later

  • Establish M&A security integration playbooks for acquired IT environmentsReduces risk of inherited security weaknesses when integrating acquired systems such as Starwood.

Detection ideas

Detect anomalous access and bulk reads from reservation databases

Alert on high-volume queries, rare admin accounts, and unusual time-of-day access to sensitive guest tables.

Data sources: Database audit logs, SIEM, Identity access logs

Detect unusual data egress from database networks

Identify large outbound transfers, especially to unfamiliar hosts or cloud storage, from database subnets.

Data sources: Proxy logs, NetFlow/flow logs, DLP alerts

Sources

Marriott discloses Starwood guest reservation database breach · Baitaphish