When Marriott International acquired Starwood Hotels and Resorts in 2016, it inherited more than 1,300 hotel properties, a loyalty program with over 100 million members, and an undiscovered Chinese intelligence operation that had been running inside Starwood's networks since at least 2014. The breach was not discovered until September 2018, when a security tool flagged an unusual database query. By then, the attacker had been inside the guest reservation database for four years, quietly exfiltrating records covering approximately 500 million guests - the second largest data breach in history by number of records at the time of disclosure.

US intelligence officials attributed the breach to a Chinese state intelligence unit, specifically one associated with the Ministry of State Security. The attribution was based on the tools, techniques, and patterns used - including a webshell and Remote Access Tool consistent with APT group tooling associated with Chinese intelligence - and on the nature of the data stolen. The Starwood reservation database was not merely a pile of credit card numbers. It contained detailed travel records: when guests stayed at Starwood properties, for how long, who they traveled with, where they came from, and where they went. For a foreign intelligence service, this data is extraordinarily valuable for identifying intelligence targets, tracking diplomats and military personnel, and building comprehensive movement patterns on individuals of interest.

The Intrusion Timeline

The intrusion began in 2014, two years before Marriott acquired Starwood. The attacker used a remote access trojan (RAT) to establish persistence on systems connected to the Starwood guest reservation database. Once inside, they moved laterally to the reservation system itself - the Starwood preferred guest (SPG) database - and began staging and exfiltrating data.

The exfiltration was not a single large dump. Evidence suggested ongoing, methodical collection over multiple years. The attacker had deep familiarity with the database structure and extracted data in ways designed to avoid triggering volumetric alerts. The operation continued through the Marriott acquisition in September 2016 - Marriott's due diligence process did not catch the intrusion, which is not uncommon; security assessments in M&A transactions often focus on financial and legal risk rather than performing thorough forensic analysis of every system in the acquired company.

In September 2018, Accenture (which Marriott had contracted to work on the Starwood systems integration) flagged an unusual query by an internal security tool. The investigation that followed discovered the RAT, the long-running exfiltration, and ultimately the scope of the breach. Marriott notified the FBI, began its forensic investigation, and prepared for disclosure.

[TECHNICAL NOTE]
The technical details of the Marriott/Starwood intrusion that were publicly disclosed focused on the web shell and RAT used to maintain persistence. The attacker used Mimikatz (the credential extraction tool) to harvest Windows credentials for lateral movement - consistent with common APT tradecraft. The primary payload was a customized version of the PlugX RAT (also known as Korplug), a modular remote access tool widely used by Chinese threat actors including APT10, APT41, and associated groups. PlugX supports modules for keylogging, file transfer, process injection, and remote shell access. The attacker also used a component called "MiMail" for credential theft. The database that was exfiltrated was the Starwood Preferred Guest (SPG) database - a SQL Server database containing reservation records. The exfiltrated records included: name, mailing address, phone number, email address, passport number, date of birth, gender, SPG loyalty account information, and reservation information including arrival date, departure date, and communication preferences. Approximately 8.6 million of the 500 million records included payment card numbers, though these were encrypted. Some passport numbers were stored as encrypted values; the investigation concluded the encryption keys were likely also obtained.

Why Travel Data Is Intelligence Gold

The public reaction to the Marriott breach focused heavily on the credit card and passport numbers - the obvious financial and identity theft risks. US intelligence officials were concerned about something different. The breach gave Chinese intelligence four years of detailed travel records for tens of millions of people, including US government employees, military personnel, intelligence officers, diplomats, and business executives who traveled internationally.

Consider what these records reveal. An intelligence analyst looking at the SPG database could identify every time a specific individual stayed at a Starwood property anywhere in the world - which properties, for how long, with what room preferences, with which credit card, traveling from and to where. This data can be cross-referenced with other intelligence to build comprehensive movement profiles. It can reveal covert travel by intelligence officers (whose cover identity might stay at hotels). It can reveal undisclosed meetings (two people who checked into the same hotel on the same night). It can reveal behavioral patterns useful for targeting recruitment approaches.

This type of "big data" intelligence collection is a signature of Chinese state intelligence operations. The OPM breach (2015, 21 million US federal employee records) combined with the Anthem breach (2015, 80 million insurance records), the Marriott breach, and smaller operations gave Chinese intelligence a remarkably detailed picture of the US government workforce. Former Director of National Intelligence James Clapper called the OPM breach "a legitimate espionage operation" - and the Marriott breach fits the same pattern.

[WARNING]
The Marriott/Starwood breach raises a significant question about M&A security due diligence. Marriott paid $13.6 billion for Starwood. That acquisition included inheriting an active, multi-year intelligence operation that Marriott did not know about and could not have discovered through standard due diligence processes. The breach ultimately cost Marriott approximately $124 million in regulatory penalties (including a £99 million GDPR fine from the UK ICO, later reduced to £18.4 million), class action settlements, and remediation costs. The Marriott case became a benchmark for how acquirers should approach security in M&A: comprehensive technical due diligence, breach notification escrow provisions in acquisition agreements, and security representations and warranties from the seller. The UK GDPR fine was particularly significant because it was one of the first major GDPR penalties and established that an organization can be liable for a breach that began before it controlled the data, if it failed to take adequate steps to discover and remediate inherited security issues after the acquisition.

Attribution and Geopolitical Context

The US government formally attributed the Starwood breach to China in 2018, part of a broader set of indictments against Chinese nationals associated with APT10. The timing was significant: the attribution came during an escalating trade dispute with China and was part of a coordinated effort with UK, Australian, Canadian, and New Zealand intelligence partners. The Chinese government denied the attribution.

The pattern of Chinese intelligence data collection operations in this period - OPM, Anthem, Marriott, and others - reflected a strategy of building comprehensive datasets on US government and military personnel, presumably for use in identifying intelligence targets and countering US intelligence activities. These are not financially motivated breaches. The stolen data has limited black market value compared to simple credit card numbers. The value is in the aggregation and analysis.

Marriott faced regulatory scrutiny across multiple jurisdictions. The UK Information Commissioner's Office initially proposed a £99.2 million GDPR fine in 2019, the second largest proposed GDPR penalty at the time. After Marriott cooperated with the investigation and demonstrated post-breach remediation steps, the fine was reduced to £18.4 million, issued in October 2020. US regulatory action was limited; the FTC did not impose a fine, accepting Marriott's remediation steps.

[IOC]
Marriott/Starwood breach indicators of compromise: the RAT used was PlugX (also known as Korplug, SOGU, Destroy RAT), with customized configuration - the specific command-and-control infrastructure has not been publicly disclosed. Credential harvesting tool: Mimikatz (sekurlsa::logonpasswords module for Windows credential extraction from LSASS memory). Web shell deployed on Starwood web-facing servers (specific shell type not publicly named). The affected systems were the Starwood Preferred Guest (SPG) reservation platform, which ran on Windows Server infrastructure. Affected records: approximately 327 million records with full details (name, address, DOB, phone, email, passport number, arrival/departure dates); approximately 173 million records with name and possibly email/other fields; approximately 8.6 million records included payment card numbers. Breach timeline: initial access 2014; continuous access through September 2018 (approximately 4 years); discovery September 8, 2018 via anomalous database query alert; disclosure November 30, 2018. Notable: Marriott acquired Starwood in September 2016 and did not discover the active breach during the 2-year integration process. Organizations that may have been affected: any guest of a Starwood-brand property (W Hotels, Sheraton, Westin, Four Points, St. Regis, The Luxury Collection, Le Meridien, Design Hotels, Aloft, Element, Tribute Portfolio) between 2014 and September 2018.