500 Million Hotel Guests Hit by Massive Marriott Data Breach
Hackers had undetected access to Marriott's Starwood reservation database for nearly four years, exposing the personal data of hundreds of millions of guests.
Published June 6, 2025

Case Details
Quick Facts
Classification:
Quick facts
One of the largest cybercrime cases in the history of the hotel industry came to light when it was revealed that hackers had gained unauthorized access to Marriott's Starwood reservation database, exposing the sensitive personal information of up to 500 million hotel guests.
The affected hotel brands include W, St. Regis, Sheraton, and Westin, among others. According to available sources, the hackers first gained access in 2014 and continued undetected for years.
Extensive Personal Data Exposed
The compromised data includes names, addresses, passport and ID numbers, dates of birth, email addresses, and credit card information. Although the credit card details were encrypted, the hackers may potentially have obtained access to the encryption keys. Marriott has been unable to confirm whether the attackers succeeded in decrypting the credit card information.
Timeline
Start of the hacker attack
Unknown hackers gain access to Starwood Hotels' reservation system for the first time
Disclosure of the data breach
Marriott informs the public about the massive data theft affecting 500 million hotel guests
Undetected for Nearly Four Years
The fact that hackers moved freely within Marriott's systems for approximately four years without being detected highlights serious data breach security failures at the hotel chain. The breach was publicly announced on a Friday — a timing that is widely regarded as a corporate tactic to limit media coverage.
Ask about this case
Answers from KrimiNyt's coverage onlyFollow this case
Get an email when a new documentary, podcast or book about 500 Million Hotel Guests Hit by Massive Marriott Data Breach appears, or when a verdict is reached.

