The international hotel group Marriott is to be fined £99.2m by the Information Commissioner’s Office after hackers accessed their Starwood guest reservation database over a period of 4 years. Initially, the company said hackers stole the details of roughly 500 million hotel guests, a number which the hotel chain later corrected to 383 million following a more thorough investigation.stole the records of 339 million guests.
Marriott International, the parent company of hotel chains including W, Westin, Le Méridien and Sheraton, admitted that personal data had been stolen in a colossal global hack of guest records. According to a post mortem of the hack, hackers stole:
- 383 million guest records
- 18.5 million encrypted passport numbers
- 5.25 million unencrypted passport numbers
- 9.1 million encrypted payment card numbers
- 385,000 card numbers that were still valid at the time of the breach
- Class-action lawsuits started piling on hours after Marriott announced its security breach.
For months the UK Watchdog has been warning that it was going to start to bare its teeth and this week it has certainly made an impression. On Monday, the ICO issued it’s first GDPR fine when British Airways received a £183m fine after a hack involving personal data of half a million of the airline’s customers, today the ICO followed this up with a proposal for a £99.2m fine for Marriott, saying that about 30 million of the hacked guest records related to residents of 31 countries in the European Economic Area. Seven million directly related to UK residents.

In a filing with the US Securities Exchange Comission today, Marriott said it plans to appeal the ICO’s fine, when formally filed.
“We are disappointed with this notice of intent from the ICO, which we will contest,” said Marriott International’s President and CEO, Arne Sorenson.
“We deeply regret this incident happened. We take the privacy and security of guest information very seriously and continue to work hard to meet the standard of excellence that our guests expect from Marriott.”
However, the ICO said Marriott had failed to undertake sufficient due diligence when it acquired Starwood and should have done more to make sure its IT systems were secure.
“The GDPR makes it clear that organisations must be accountable for the personal data they hold. This can include carrying out proper due diligence when making a corporate acquisition, and putting in place proper accountability measures to assess not only what personal data has been acquired, but also how it is protected,” said Information Commissioner Elizabeth Denham.
“Personal data has a real value so organisations have a legal duty to ensure its security, just like they would do with any other asset. If that doesn’t happen, we will not hesitate to take strong action when necessary to protect the rights of the public,” Denham said.
The only real surprise is that the realisation that the GDPR was a major event and that that the ICO, whose fining powers were previously limited to £500,000, is a regulator to be feared, has taken so long to be acknowledged. There can no longer be any ambiguity about the approach that the ICO will take where security arrangements and/or processes are deemed “poor”. The ICO is clear that they will apply fines to smaller organisations on a sliding scale of percentages, based on an entire groups global turnover.
These developments are very welcome. Fraud is ultimately a cost to everyone. SMB’s and developing organisations and even companies that count their customers in the tens of millions – think tech and social media giants – finally have to take notice – or face the consequences.








