People search Marriott data breach timeline because the brand sits on billions of accounts, credentials, and cloud workloads. BreachHistory indexes 9 Marriott-linked incidents, with headline counts up to 500M+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.
Why Marriott breach history matters
Marriott operates in Technology (United States). Across indexed rows, recurring themes include credential theft and social engineering, cloud and database misconfiguration. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.
Full timeline through 2026
2024 — 344M breach history (2014–2020)
Cataloged incident. FTC and 49 states settled over multiple breaches 2014–2020 affecting 344M+ customers. Passport info, payment cards, loyalty numbers, DOB, emails. Marriott paid $52M. Exposed categories include Email addresses, Passwords, Dates of birth, Payment card details, Passport numbers, Payment information. BreachHistory cites approximately 344M+ affected records in this row. See the mar2024ftc and canonical BreachHistory entry.
2020 — — 5.2M guests
Cataloged incident. Credential stuffing. 5.2M guests. Exposed categories include Names, emails, addresses, and other PII. BreachHistory cites approximately 52 affected records in this row. See the marriott2020 and canonical BreachHistory entry.
2020 — — Marriott Hotels: Insider, 520,000 records
Cataloged incident. Guest records were accessed using the logins of two employees between mid-Jan and end of Feb. Exposed categories include Personal and demographic data. BreachHistory cites approximately 520K+ affected records in this row. See the marriott2020-iib and canonical BreachHistory entry.
2020 — — Marriott International: Poor security / misconfiguration, 5,200,000 records
Cataloged incident. Data breach reported. hotel organization. Method: poor security. Source: Wikipedia List of data breaches. Exposed categories include Personal and demographic data. BreachHistory cites approximately 5.2M+ affected records in this row. See the marriott2020-5200000-wiki2 and canonical BreachHistory entry.
2018 — Starwood reservation system breach (2014–2018)
Cataloged incident. Unauthorized access to Starwood's guest reservation database from 2014 until discovery in 2018. Exposed names, addresses, passport numbers, travel details, and encrypted payment cards. Exposed categories include Names, Addresses, Payment card details, Passport numbers, Credentials, Payment information. BreachHistory cites approximately 500M+ affected records in this row. See the kxlc and canonical BreachHistory entry.
2018 — — Marriott International: Sensitive data on customer to all Starwood hotels…
Cataloged incident. Nov 2018. Sensitive data on customer to all Starwood hotels (including Sheraton, Regis, W Hotels) leaked since 2014. Credit card details and some passport info. The size of the hack was downsized from 500 million to 383 million following an investigation. BreachHistory cites approximately 383M+ affected records in this row. See the marriott2018 and canonical BreachHistory entry.
2018 — — Marriott International: Hacking, 38,300,000 records
Cataloged incident. Hackers breached the reservation system of all Starwood hotels, including Sheraton, Westin and Le Meridien. Personal information, credit card details and passport info dating back to 2014 was stolen. Exposed categories include Personal and demographic data. BreachHistory cites approximately 38.3M+ affected records in this row. See the marriott2018-iib and canonical BreachHistory entry.
2011 — — Marriott International: An unknown number of customer payment slips were…
Cataloged incident. An unknown number of customer payment slips were lost during shipping. Timeshare maintenance fee payment slips were processed by a bank and shipped back to Marriott. The box of slips arrived damaged and had some of the slips missing. Timeshare owners' names, credit card numbers and expiration dates, and addresses were exposed. Exposed categories include Personal information. No attested victim count is published for this row yet. See the marriott2011 and canonical BreachHistory entry.
2005 — — Marriott International: It is unclear whether backup computer tapes with…
Cataloged incident. It is unclear whether backup computer tapes with credit card account information and Social Security numbers were lost or stolen from headquarters during November. Employees and time-share owners and customers were affected. Exposed categories include Personal information. BreachHistory cites approximately 206K+ affected records in this row. See the marriott2005 and canonical BreachHistory entry.
Patterns and analysis
- Credential theft and social engineering — appears across multiple Marriott catalog entries; prioritize controls that address this class of failure.
- Cloud and database misconfiguration — appears across multiple Marriott catalog entries; prioritize controls that address this class of failure.
- Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
- 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.
What to do if you may be affected
- Step 1: Enable phishing-resistant MFA on every account tied to this brand.
- Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
- Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
- Step 4: Review OAuth app permissions and revoke unused third-party integrations.
- Step 5: Bookmark the Marriott company page for new 2026+ disclosures.
Canonical BreachHistory hub
Explore every indexed row: breachhistory.com/marriott · Latest: mar2024ftc.
Sources: BreachHistory catalog (9 rows for Marriott), company and regulator disclosures cited in individual breach records.