---
title: "The Marriott Hack: A Cautionary Tale for Corporate Acquisitions"
description: The case of the Marriott hack is an invaluable case study for any organization involved in cyber security due diligence before a  merger or acquisition.
image: https://www.truvantis.com/hubfs/Blogs/The%20Marriott%20Hack%20A%20Cautionary%20Tale%20for%20Corporate%20Acquisitions.jpeg
---

[![truvantis-logo-reverse@2x](https://www.truvantis.com/hs-fs/hubfs/Truvantis%20Logo/truvantis-logo-reverse@2x.png?width=1117&height=250&name=truvantis-logo-reverse@2x.png "truvantis-logo-reverse@2x")](https://www.truvantis.com)

[![truvantis-logo-main@2x-1](https://www.truvantis.com/hs-fs/hubfs/Truvantis%20Logo/truvantis-logo-main@2x-1.png?width=1117&height=250&name=truvantis-logo-main@2x-1.png "truvantis-logo-main@2x-1")](https://www.truvantis.com/)

**

## Blog

![](https://www.truvantis.com/hs-fs/hubfs/Truvantis%20Logo/truvantis-logo-main@2x-1.png?length=200)

# The Marriott Hack: A Cautionary Tale for Corporate Acquisitions

 May 15, 2020

The case of the Marriott hack is, at once, an alarming prospect for the chain’s previous guests and an invaluable case study for any organization involved in any kind of merger. At the very least, it serves as a cautionary tale for businesses that ignore their due diligence in respect to cybersecurity during acquisitions.

The issue started in 2014 when hackers were able to expose and bypass the [Starwood Hospitality Group’s](https://www.marriott.com/default.mi?program=spg) security system. Starwood operates several popular hotel chains, including Westin, Sheraton, Aloft, and W Hotels. Marriott—the fourth largest hotel chain in the world—acquired the group in 2016, and this past November, they had to break the news that as many as 500 million customers’ data may have been compromised. The chain now estimates that the number of customers impacted is closer to 383 million, but that figure is still more than enough to constitute the largest breach in the history of the travel industry.

It is believed that a significant portion of those affected only had relatively inconsequential information, like names and email addresses, stolen. However, others may be in more trouble as it is believed that certain customers had different combinations of various data, including names, phone numbers, home and email addresses, birthdays, genders, and reservation information stolen. Most alarmingly, hackers were able to access as many as 5.25 million unencrypted passport numbers and data from 354,000 active and unexpired credit cards. The FBI believes that the perpetrators behind the hack were likely working on behalf of the [Chinese Ministry of State Security](https://bgr.com/2018/12/12/china-hack-marriott-state-security-ministry/)—the Chinese equivalent of the CIA.

There is plenty to learn from this situation, but organizations interested in or actively pursuing acquisitions can take the most away from it. Hackers were in Starwood’s security system for two years both before and after they were acquired by Marriott, but the fundamental flaws and vulnerabilities in their security program still went undiscovered during and after the merger. This whole situation and its consequences perfectly accentuate exactly how crucial a comprehensive and thorough cybersecurity vetting process is to a corporate takeover.

#### Related Articles By Topic

[Penetration Testing](https://www.truvantis.com/blog/tag/penetration-testing) [Security Program](https://www.truvantis.com/blog/tag/security-program) [Risk Assessment](https://www.truvantis.com/blog/tag/risk-assessment)

### Subscribe Here!

### Recent Posts

### Related Articles By Topic

- [Security Program (76)](https://www.truvantis.com/blog/tag/security-program)
- [vCISO (38)](https://www.truvantis.com/blog/tag/vciso)
- [CISO (35)](https://www.truvantis.com/blog/tag/ciso)
- [PCI DSS (28)](https://www.truvantis.com/blog/tag/pci-dss)
- [SOC2 (28)](https://www.truvantis.com/blog/tag/soc2)
- [Penetration Testing (27)](https://www.truvantis.com/blog/tag/penetration-testing)
- [Privacy (26)](https://www.truvantis.com/blog/tag/privacy)
- [Risk Assessment (19)](https://www.truvantis.com/blog/tag/risk-assessment)
- [CIS Controls (12)](https://www.truvantis.com/blog/tag/cis-controls)
- [Red Teaming (8)](https://www.truvantis.com/blog/tag/red-teaming)
- [HIPAA (7)](https://www.truvantis.com/blog/tag/hipaa)
- [Threat Intelligence (7)](https://www.truvantis.com/blog/tag/threat-intelligence)
- [ISO27001 (6)](https://www.truvantis.com/blog/tag/iso27001)
- [CCPA (5)](https://www.truvantis.com/blog/tag/ccpa)
- [CPRA (2)](https://www.truvantis.com/blog/tag/cpra)
- [GDPR (2)](https://www.truvantis.com/blog/tag/gdpr)
- [Ransomware (2)](https://www.truvantis.com/blog/tag/ransomware)
- [Red Team (2)](https://www.truvantis.com/blog/tag/red-team)
- [HITRUST (1)](https://www.truvantis.com/blog/tag/hitrust)

[See all](https://www.truvantis.com/blog/marriott-hack#)

Contact Us

Let's chat about your security programs.

[![Schedule a call](https://hubspot-no-cache-na2-prod.s3.amazonaws.com/cta/default/4366475/0b8e00cd-457a-4115-81ca-16a8b3b785a2.png)](https://hubspot-cta-redirect-na2-prod.s3.amazonaws.com/cta/redirect/4366475/0b8e00cd-457a-4115-81ca-16a8b3b785a2)

[![Contact Us](https://hubspot-no-cache-na2-prod.s3.amazonaws.com/cta/default/4366475/ccf084a3-d095-4418-80d6-891f8fdade46.png)](https://hubspot-cta-redirect-na2-prod.s3.amazonaws.com/cta/redirect/4366475/ccf084a3-d095-4418-80d6-891f8fdade46)

### Recent Articles

![Truvantis - Cybersecurity Maturity - One Size Does Not Fit All ](https://www.truvantis.com/hubfs/Blogs/Cybersecurity%20Maturity%20-%20One%20Size%20Does%20Not%20Fit%20All.png)

 PCI DSS, CIS Controls, Security Program, Privacy, ISO27001 

[ Cybersecurity Maturity - One Size Does Not Fit All – Rick Folkerts ](https://www.truvantis.com/blog/cybersecurity-maturity-one-size-does-not-fit-all-rick-folkert)

 It's common knowledge that enterprise organizations need effective security, privacy and compliance programs to survive and grow. There are a handful of generic best practices but beyond that, cybersecurity programs must be tailored to...

[Read more **](https://www.truvantis.com/blog/cybersecurity-maturity-one-size-does-not-fit-all-rick-folkert)

![The Silver Bullet Defense to Ransomware – by Andy Cottrell](https://www.truvantis.com/hubfs/Blogs/The%20Silver%20Bullet%20Defense%20to%20Ransomware%20%E2%80%93%20by%20Andy%20Cottrell.png)

 Ransomware 

[ The Silver Bullet Defense to Ransomware – by Andy Cottrell ](https://www.truvantis.com/blog/the-silver-bullet-defense-to-ransomware-by-andy-cottrell)

 In an era of cost-cutting, downsizing and generally insufficient budgets for everything, we are often asked, what is the one, main thing to do to protect against a ransomware attack? According to Statista, in 2022, there were 493.33 mi...

[Read more **](https://www.truvantis.com/blog/the-silver-bullet-defense-to-ransomware-by-andy-cottrell)

![Cryptographic Agility – by Jeff Hall (the ’PCI Guru’)](https://www.truvantis.com/hubfs/Blogs/Cryptographic%20Agility%20%E2%80%93%20by%20Jeff%20Hall%20(the%20%E2%80%99PCI%20Guru%E2%80%99).png)

 Security Program 

[ Cryptographic Agility – by Jeff Hall (the ’PCI Guru’) ](https://www.truvantis.com/blog/cryptographic-agility)

 With the advent of quantum computing, a new threat has been added to the information security mix. The threat is today’s secure cryptography may not be secure once quantum computers reach their potential. The threat to cryptography has...

[Read more **](https://www.truvantis.com/blog/cryptographic-agility)

[![truvantis-logo-white@2x-1](https://www.truvantis.com/hs-fs/hubfs/Truvantis%20Logo/truvantis-logo-white@2x-1.png?width=1117&height=250&name=truvantis-logo-white@2x-1.png "truvantis-logo-white@2x-1")](https://www.truvantis.com/)

[info@truvantis.com](mailto:info@truvantis.com)

+1 (415) 422-9844

<https://www.facebook.com/truvantis> <https://www.linkedin.com/company/truvantis> <https://twitter.com/truvantis?lang=en>

© 2024 Truvantis, Inc All Rights Reserved.

[Privacy Policy](https://www.truvantis.com/privacy-policy)    [Terms of Service ](https://www.truvantis.com/terms-of-service)

![](https://px.ads.linkedin.com/collect/?pid=2614233&fmt=gif) ![](https://ws.zoominfo.com/pixel/dnjpprEKcMtv41HRInFR)