Marriott International Data Breach History
WebsiteMarriott International is an American multinational company that operates and franchises hotels. Fortune 500.
This page shows all data breaches of Marriott International. View the complete breach timeline, records exposed, root causes, and AI breach risk score. BreachHistory tracks disclosed data breaches worldwide.
Data Breach Timeline — All Marriott International Breaches
- 2024 2024 FTC settlement — 344M breach history (2014–2020) 344.0M records Share
- 2020 2020 — 5.2M guests Unknown records Share
- 2020 2020 — Marriott Hotels: Insider, 520,000 records 520.0K records Share
- 2020 2020 — Marriott International: Poor security / misconfiguration, 5,200,000 records 5.2M records Share
- 2018 Starwood reservation system breach (2014–2018) 500.0M records Share
Marriott International Data Breach Summary
This page tracks the Marriott International data breach history and cybersecurity incidents affecting Marriott International (United States). BreachHistory currently indexes 9 publicly disclosed or catalogued incidents spanning 2005 through 2024, with approximately 1.3 billion records reported as exposed across all indexed events. These totals may include overlapping datasets or third-party estimates and should not be interpreted as unique affected users.
The Marriott International breach timeline includes major data breaches, cyber attacks, data leaks, credential exposures, API abuse, and other security incidents. Each incident provides details on the estimated records exposed, attack method, affected data types, and supporting public sources. Currently, 0 incidents are company-confirmed.
Largest Marriott International Data Breaches
The largest indexed incidents include the 2018 Starwood reservation system breach (2014 — 2018), the 2018 — Marriott International: Sensitive data on customer to all Starwood hotels…, and the 2024 FTC settlement — 344M breach history (2014 — 2020), along with additional historical incidents involving exposed passwords, public databases, and large-scale data scraping. Record counts originating from threat actors or leak sites should be treated as estimates unless confirmed by Marriott International or a regulator. Below is the list of large data breaches:
- 2018 Starwood reservation system breach (2014–2018) — about 500.0M records exposed · Catalogued incident
- 2018 2018 — Marriott International: Sensitive data on customer to all Starwood hotels… — about 383.0M records exposed · Catalogued incident
- 2024 2024 FTC settlement — 344M breach history (2014–2020) — about 344.0M records exposed · Catalogued incident
- 2018 2018 — Marriott International: Hacking, 38,300,000 records — about 38.3M records exposed · Catalogued incident
- 2020 2020 — Marriott International: Poor security / misconfiguration, 5,200,000 records — about 5.2M records exposed · Catalogued incident
- 2020 2020 — Marriott Hotels: Insider, 520,000 records — about 520.0K records exposed · Catalogued incident
- 2005 2005 — Marriott International: It is unclear whether backup computer tapes with… — about 206.0K records exposed · Catalogued incident
What Information Was Exposed?
Depending on the incident, exposed data may include email addresses, passwords and login credentials, names, physical addresses, payment card and financial account data, health and medical (PHI) records, and other personal information (PII). The exact data varies between incidents, so review each breach page before assuming your information was affected.
Marriott International Data Breach 2026
At the time of this update, no Marriott International data breach has been catalogued for 2026. New incidents are added as official disclosures, regulatory filings, or credible cybersecurity reports become available.
What To Do If You Were Affected
If you believe your account may have been involved in a Marriott International data breach, change any reused passwords, enable multi-factor authentication (MFA), monitor your account for suspicious activity, and be cautious of phishing emails or fake breach notifications.
This Marriott International breach history is maintained by BreachHistory using public disclosures, regulatory filings, security research, and clearly labelled third-party claims. For the complete breach timeline, records exposed, incident details, and AI Breach Risk Score, explore the sections on this page.