Marriott disclosed that attackers had compromised the Starwood guest reservation database, exposing records tied to hundreds of millions of guests who stayed at Starwood properties on or before Sept. 10. The company initially said the incident could affect up to 500 million guests, later revising the figure to fewer than 383 million, while stating that at least 327 million records contained personal data such as names, mailing addresses, phone numbers, email addresses, passport numbers, birth dates, gender, and in some cases encrypted payment card details. The breach prompted law-enforcement notification and regulatory scrutiny, including an investigation announced by New York's attorney general.
MGM Resorts separately faced repeated fallout from cyber incidents affecting hotel guests. Guest details for 10.6 million MGM customers were later found posted on a hacking forum, and in a subsequent cyberattack the company said intruders stole customer information including Social Security numbers and passport data while disrupting reservations, casino gaming, digital room keys, websites, and mobile apps across most properties. MGM estimated the September attack would cut results by about $100 million and add roughly $10 million in response costs, with reporting attributing the intrusion to social-engineering tactics linked to Scattered Spider and ALPHV/BlackCat.

See attribution, scope, and your downstream exposure.
12 events from the most recent confirmed update back to the earliest known activity.
In an SEC filing, MGM said the September 2023 cyberattack would reduce third-quarter results by about $100 million, with less than $10 million in additional consulting, legal, and advisory costs. It also disclosed that customer personal information, including Social Security numbers and passport data for some individuals, had been exposed, though no payment card data was accessed.
By early October 2023, MGM said most affected systems had been restored and properties had largely returned to normal operations. The company also said it was notifying impacted customers and offering identity protection or credit monitoring services.
Security researchers and reporting attributed the MGM intrusion to a social engineering attack associated with Scattered Spider, allegedly working with the ALPHV/BlackCat ransomware gang.
MGM Resorts said it discovered a cyberattack on September 11, 2023 and shut down systems to contain it. The incident caused widespread disruption across casino and hotel operations, affecting reservations, gaming, digital keys, websites, and mobile apps.
On or around July 13, 2020, reporting said a hacker was selling details of 142 million MGM hotel guests on the dark web. The sale represented a major escalation from the earlier exposure of 10.6 million MGM guest records posted on a hacking forum.
Details belonging to 10.6 million MGM hotel guests were posted on a hacking forum, exposing customer information from a prior incident affecting the hotel and casino operator.
Marriott disclosed that the Starwood breach exposed about 5.25 million unencrypted passport numbers and roughly 20.3 million encrypted passport numbers. The update refined the scope of sensitive data compromised beyond the company's initial November 2018 disclosure.
Reporting on December 11-12, 2018 said investigators had traced the Marriott Starwood breach to a Chinese intelligence-gathering campaign. The attribution reframed the incident as part of a broader espionage effort rather than only a large-scale data breach affecting hotel guests.
Following Marriott's disclosure, New York Attorney General Barbara Underwood announced an investigation into the Starwood data breach.
On November 30, 2018, Marriott publicly disclosed the Starwood database breach, initially saying up to 500 million guests could be affected and that at least 327 million records contained personal data such as contact details, passport numbers, birth dates, and some payment card information. The company said it had reported the incident to law enforcement.
Marriott said it learned on November 19, 2018 that an unauthorized party had copied and encrypted information from the Starwood guest reservation database. The breach potentially affected guests who stayed at Starwood properties on or before September 10, 2018.
Marriott later said unauthorized access to the Starwood guest reservation database dated back to 2014, indicating the compromise had persisted for years before discovery.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
8 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourcecybersecuritydive.com
Open sourcezdnet.com
Open sourcezdnet.com
Open sourcecnet.com
Open sourceaxios.com
Open sourcezdnet.com
Open sourcefoxbusiness.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.