MalwareRansomwareStolen CredentialsDelayed DiscoveryMulti-Stage ChainData ExfiltratedData EncryptedCustomer Data InvolvedRansom DemandedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALSCriticalContained
MARRIOTT INTERNATIONAL, INC.
bd_41ce13df784b7b67 · schema v1 · pii pii-v1
Full breach record for MARRIOTT INTERNATIONAL, INC. →Marriott International disclosed a security incident involving the Starwood Guest Reservation Database. Unauthorized access occurred starting in 2014. In 2018, an unauthorized party copied and encrypted data, demanding ransom. Marriott decrypted the data, confirming it came from the Starwood database. Approximately 500 million guests were affected, with 327 million having names, addresses, passport numbers, and some having encrypted payment card data. Marriott engaged security experts, notified law enforcement, and offered one year of WebWatcher monitoring.
California clockDiscovered Sep 8, 2018 → Notified Nov 30, 201883d ✗ CA 60-day late12 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_8a9e56980902ec7bOregon State AGfiled 2018-11-30Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-142258
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 30, 2018
- Raw hash
- ff87ebc3c9374d5d0ac8ce8172ea1984370c37f797f0785d83f39523c3d44ef6
Reporting entity
- Name
- MARRIOTT INTERNATIONAL, INC.norm: marriott international
- Domain
- marriott.com
Victim entity
- Name
- MARRIOTT INTERNATIONAL, INC.norm: marriott international
- Domain
- marriott.com
Incident
- Discovered
- Sep 8, 2018
- Materiality determined
- Nov 30, 2018
- Notification sent
- Nov 30, 2018
- Affected individuals
- 500,000,000
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported this incident to law enforcementNotifying regulatory authorities
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 12 weeks(83 days from discovery to filing)
- Compliance flags
- CA 60-day late · 83d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 8, 2018→ Notified: Nov 30, 201883d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.