When Marriott International acquired Starwood Hotels and Resorts in 2016, it inherited more than 1,300 hotel properties, a loyalty program with over 100 million members, and an undiscovered Chinese intelligence operation that had been running inside Starwood's networks since at least 2014. The breach was not discovered until September 2018, when a security tool flagged an unusual database query. By then, the attacker had been inside the guest reservation database for four years, quietly exfiltrating records covering approximately 500 million guests - the second largest data breach in history by number of records at the time of disclosure.
US intelligence officials attributed the breach to a Chinese state intelligence unit, specifically one associated with the Ministry of State Security. The attribution was based on the tools, techniques, and patterns used - including a webshell and Remote Access Tool consistent with APT group tooling associated with Chinese intelligence - and on the nature of the data stolen. The Starwood reservation database was not merely a pile of credit card numbers. It contained detailed travel records: when guests stayed at Starwood properties, for how long, who they traveled with, where they came from, and where they went. For a foreign intelligence service, this data is extraordinarily valuable for identifying intelligence targets, tracking diplomats and military personnel, and building comprehensive movement patterns on individuals of interest.
The Intrusion Timeline
The intrusion began in 2014, two years before Marriott acquired Starwood. The attacker used a remote access trojan (RAT) to establish persistence on systems connected to the Starwood guest reservation database. Once inside, they moved laterally to the reservation system itself - the Starwood preferred guest (SPG) database - and began staging and exfiltrating data.
The exfiltration was not a single large dump. Evidence suggested ongoing, methodical collection over multiple years. The attacker had deep familiarity with the database structure and extracted data in ways designed to avoid triggering volumetric alerts. The operation continued through the Marriott acquisition in September 2016 - Marriott's due diligence process did not catch the intrusion, which is not uncommon; security assessments in M&A transactions often focus on financial and legal risk rather than performing thorough forensic analysis of every system in the acquired company.
In September 2018, Accenture (which Marriott had contracted to work on the Starwood systems integration) flagged an unusual query by an internal security tool. The investigation that followed discovered the RAT, the long-running exfiltration, and ultimately the scope of the breach. Marriott notified the FBI, began its forensic investigation, and prepared for disclosure.
Why Travel Data Is Intelligence Gold
The public reaction to the Marriott breach focused heavily on the credit card and passport numbers - the obvious financial and identity theft risks. US intelligence officials were concerned about something different. The breach gave Chinese intelligence four years of detailed travel records for tens of millions of people, including US government employees, military personnel, intelligence officers, diplomats, and business executives who traveled internationally.
Consider what these records reveal. An intelligence analyst looking at the SPG database could identify every time a specific individual stayed at a Starwood property anywhere in the world - which properties, for how long, with what room preferences, with which credit card, traveling from and to where. This data can be cross-referenced with other intelligence to build comprehensive movement profiles. It can reveal covert travel by intelligence officers (whose cover identity might stay at hotels). It can reveal undisclosed meetings (two people who checked into the same hotel on the same night). It can reveal behavioral patterns useful for targeting recruitment approaches.
This type of "big data" intelligence collection is a signature of Chinese state intelligence operations. The OPM breach (2015, 21 million US federal employee records) combined with the Anthem breach (2015, 80 million insurance records), the Marriott breach, and smaller operations gave Chinese intelligence a remarkably detailed picture of the US government workforce. Former Director of National Intelligence James Clapper called the OPM breach "a legitimate espionage operation" - and the Marriott breach fits the same pattern.
Attribution and Geopolitical Context
The US government formally attributed the Starwood breach to China in 2018, part of a broader set of indictments against Chinese nationals associated with APT10. The timing was significant: the attribution came during an escalating trade dispute with China and was part of a coordinated effort with UK, Australian, Canadian, and New Zealand intelligence partners. The Chinese government denied the attribution.
The pattern of Chinese intelligence data collection operations in this period - OPM, Anthem, Marriott, and others - reflected a strategy of building comprehensive datasets on US government and military personnel, presumably for use in identifying intelligence targets and countering US intelligence activities. These are not financially motivated breaches. The stolen data has limited black market value compared to simple credit card numbers. The value is in the aggregation and analysis.
Marriott faced regulatory scrutiny across multiple jurisdictions. The UK Information Commissioner's Office initially proposed a £99.2 million GDPR fine in 2019, the second largest proposed GDPR penalty at the time. After Marriott cooperated with the investigation and demonstrated post-breach remediation steps, the fine was reduced to £18.4 million, issued in October 2020. US regulatory action was limited; the FTC did not impose a fine, accepting Marriott's remediation steps.