Yes, a massive data breach exposed the personal information of millions of Marriott hotel guests. In November 2018, Marriott discovered that intruders had accessed its Starwood Hotels & Resorts Worldwide reservation database for more than four years without detection, compromising 133.7 million guest records globally, with 131.5 million U.S. guests affected. The breach exposed names, email addresses, phone numbers, dates of birth, passport numbers, loyalty program account information, and some payment card data—information that remained vulnerable from July 2014 through September 2018 while the company remained unaware of the intrusion.
The incident became one of the largest hotel industry data breaches on record, triggering both government investigations and class action lawsuits. In October 2024, the Federal Trade Commission and 49 U.S. states plus the District of Columbia announced a $52 million settlement with Marriott to resolve liability for this breach and two other incidents. However, the legal landscape shifted in June 2025 when a federal appeals court reversed class action certification, ruling that an arbitration clause in Marriott Rewards membership terms required disputes to be settled individually rather than as a class. This decision fundamentally changed how affected guests can seek compensation.
Table of Contents
- How Did Marriott’s Data Breach Happen and What Was Its Full Scope?
- What Personal Information Was Exposed in the Marriott Breach?
- What Was the Government’s Response and Settlement?
- Why Did the Class Action Lawsuit Get Reversed?
- What Are the Practical Challenges for Affected Guests Now?
- What Should Affected Marriott Guests Do?
- What Changes Has Marriott Made Since the Breach?
- Conclusion
How Did Marriott’s Data Breach Happen and What Was Its Full Scope?
The Starwood reservation database that Marriott breached had been targeted by intruders who gained unauthorized access in July 2014, just before Marriott acquired Starwood Hotels in 2016. The attackers remained inside the system undetected for over four years—a span of more than 48 months during which they could access guest reservation information continuously. Marriott did not discover the intrusion until November 2018, when internal security tools finally detected the suspicious activity. By that time, the damage was already extensive: approximately 133.7 million guest records containing sensitive personal details had been exposed.
The breach affected guests from around the world, but the damage in the United States was particularly severe, with 131.5 million U.S. guests impacted. The intruders accessed a reservation database that contained information about guests who had stayed at Starwood properties over this extended period. For many guests, a single hotel stay—a business trip, vacation, or conference attendance years earlier—meant their personal information was exposed without their knowledge. The length of the breach window means some guests who stayed at Starwood properties in 2014 or 2015 did not discover their information was compromised until years later, well after the incident occurred.

What Personal Information Was Exposed in the Marriott Breach?
The data exposed in the Marriott breach included comprehensive personal and financial details that criminals could use for identity theft, fraud, or targeted scams. Names, email addresses, phone numbers, and dates of birth were all compromised, giving attackers basic identification information they could cross-reference with other data sources. More seriously, the breach exposed passport numbers—information that sophisticated criminals could use to commit international fraud or identity theft—along with loyalty program account details that could allow unauthorized access to Marriott rewards accounts and accumulated points.
Some guests’ payment card information was also accessed during the breach, though Marriott stated that most card data was encrypted or masked. The selective exposure of payment card data created a two-tier risk: guests whose card information remained encrypted faced lower immediate risk from fraud, but those whose unencrypted card data was taken faced exposure to financial theft. A significant limitation of the settlement is that guests have had no easy way to know which category they fall into, leaving many uncertain whether their financial information was specifically compromised. Additionally, the combination of passport numbers with other identifiers made affected guests vulnerable to a broader range of crimes, from travel-related fraud to synthetic identity theft.
What Was the Government’s Response and Settlement?
The Federal Trade Commission and state attorneys general took action against Marriott for its handling of the Starwood breach alongside two other separate data breaches the company experienced between 2014 and 2020 affecting 344 million customers globally. On October 9, 2024, regulators announced a $52 million settlement with Marriott to resolve liability for inadequate security practices across all three incidents. The settlement involved 49 U.S. states, the District of Columbia, and the FTC, representing one of the largest coordinated data breach settlements by state attorneys general.
Under the settlement, Marriott was required to strengthen its data security practices by implementing a dynamic risk-based approach and establishing specific consumer protections. The company must now conduct regular security assessments, maintain incident response plans, implement multi-factor authentication for administrative accounts, and monitor its systems for unauthorized access. However, the $52 million settlement was distributed among states and the FTC—not directly to individual affected guests. A comparison to other major data breaches shows the amount was significant but not extraordinary relative to the number of people affected, averaging roughly 39 cents per affected guest when divided across the 133 million breached records, a figure that illustrates the limited individual compensation through regulatory settlements.

Why Did the Class Action Lawsuit Get Reversed?
Many affected guests filed a class action lawsuit seeking compensation directly, with Maldini v. Marriott International, Inc. serving as the primary case. The lawsuit advanced through the courts until June 3, 2025, when the 4th Circuit Court of Appeals issued a decision that halted class action proceedings entirely. The court ruled that the arbitration clause buried in the Marriott Rewards loyalty program’s terms of service required disputes to be resolved through individual arbitration rather than as a class action lawsuit.
This arbitration clause is a critical limitation that most guests never knowingly agreed to. When Marriott Rewards members enrolled in the loyalty program, the terms of service included a binding arbitration agreement that prevented class action claims. The 4th Circuit’s ruling meant that the class certification was vacated, and affected guests cannot band together to pursue claims collectively. Instead, any guest wishing to seek compensation must file an individual arbitration claim against Marriott—a process that is far more costly and time-consuming than participating in a class action. This creates a significant tradeoff: class actions pool resources and spread legal costs, while individual arbitration typically requires hiring a lawyer personally or navigating the process alone, making it impractical for many guests to pursue claims for modest damages.
What Are the Practical Challenges for Affected Guests Now?
The reversal of class certification leaves affected guests facing significant practical obstacles to seeking compensation. Without a class action framework, each guest must file an individual arbitration claim, which requires knowledge of the process, ability to document their losses, and often the expense of hiring an attorney. Most guests will never learn about this option, and those who do may determine that the cost of pursuing a claim exceeds any realistic recovery.
Many guests cannot quantify precise financial losses from the breach—they did not experience identity theft or fraud—making it difficult to claim specific damages in arbitration. A warning to guests: arbitration agreements often include confidentiality clauses that prevent winners from discussing their settlements publicly, and arbitration outcomes are not precedent-setting like class action verdicts. Additionally, the statute of limitations for bringing claims has likely begun running, meaning guests have a limited time window before they lose the right to pursue any compensation entirely. For guests who did experience fraud or identity theft following the breach, they face the burden of proving the data breach caused their specific losses—a connection that may be difficult to establish when years have passed since the breach occurrence and breach discovery.

What Should Affected Marriott Guests Do?
Guests who believe they were affected by the Marriott breach should first verify their status by checking whether they stayed at any Starwood Properties (including Sheraton, Westin, St. Regis, W Hotels, Four Points, Aloft, or Element brands) between July 2014 and September 2018. Marriott established a dedicated website where guests can enter their confirmation number from a reservation during this period to determine if their information was compromised.
Affected guests should monitor their credit reports using free services available from the three major credit reporting bureaus—Equifax, Experian, and TransUnion—to watch for unauthorized accounts or inquiries. For guests considering arbitration claims, consulting with an attorney who specializes in data breach litigation may be worthwhile, particularly if they have documented losses like identity theft, fraudulent credit card charges, or compromised passport-related incidents. Marriott agreed to provide complimentary credit monitoring and identity theft protection services to affected guests, so claiming these benefits is a practical first step that requires no legal action.
What Changes Has Marriott Made Since the Breach?
Since the 2018 discovery of the Starwood breach, Marriott has invested significantly in security infrastructure as part of its post-incident response and the obligations imposed by the FTC settlement. The company implemented additional encryption protocols, strengthened access controls for its reservation systems, and increased the frequency of security audits. Marriott also hired additional cybersecurity personnel and integrated new threat-detection technologies designed to identify unauthorized access attempts more quickly than the four-year undetected intrusion that characterized the original breach.
Looking forward, the hotel industry faces ongoing pressure to secure vast databases of guest information that contain passport numbers, financial data, and other sensitive details. Marriott’s breach demonstrated that even major corporations with significant resources can fail to detect intruders for extended periods, raising questions about the adequacy of security measures across the hospitality industry. For guests booking hotels, the incident serves as a reminder that data breaches involving third parties like reservation systems are often beyond individual consumer control, even when traveling with trusted hotel brands.
Conclusion
The Marriott data breach exposed 133.7 million guest records over a four-year period and remains one of the largest hospitality industry breaches on record. The $52 million FTC settlement in October 2024 addressed inadequate security practices, but that regulatory action provides limited direct compensation to affected guests. The June 2025 reversal of class action certification by the 4th Circuit Court of Appeals fundamentally changed how affected guests can seek recourse, requiring individual arbitration rather than collective legal action—a shift that makes compensation far less accessible for the vast majority of the 131.5 million U.S.
guests whose information was compromised. Affected guests who believe their information was breached should verify their exposure, monitor their credit reports, and consider whether individual arbitration claims are worthwhile given the complexity and potential costs involved. Marriott’s commitment to enhanced security measures reflects lessons learned from this breach, but the incident underscores the ongoing vulnerability of guest data in the hotel industry and the importance of monitoring accounts and credit profiles for years after any major data breach discovery.
You Might Also Like
- U-Haul Data Breach Class Action Claims Customer Driver’s License Information Was Exposed
- Travelers Data Breach Class Action Claims Insurance Customer Information Was Exposed
- MGM Resorts Data Breach Class Action Claims Guest Information Was Exposed
Open Settlements You Can Claim Now
Browse current class action settlements accepting claims — several require no proof of purchase:
