Recommended Free Tools
Marriott originally said that payment-card numbers and certain passport numbers stolen in the Starwood reservation-database breach were protected with AES-128 encryption. In an April 17, 2024 update, the company said it had later determined that payment-card numbers and some passport numbers were protected with SHA-1 instead. SHA-1 is a hashing algorithm, not reversible encryption. The correction makes Marriott’s original description inaccurate, but it does not by itself prove that the company intentionally fabricated the statement or that every compromised record was stored in plaintext.
The short version
- Marriott disclosed unauthorized access to Starwood’s guest database on November 30, 2018, initially estimating that information relating to about 500 million guests could be involved.
- Its disclosure described payment-card numbers and certain passport numbers as protected with AES-128 encryption.
- After an April 10, 2024 federal-court hearing, Marriott reportedly acknowledged that AES-128 had not been used during the relevant period. CSO Online reported that the judge ordered a website correction; hearing-specific details should be read as that publication’s account unless an official transcript or docket filing is consulted.
- Marriott’s April 17, 2024 update said its earlier determination was wrong and that payment-card numbers and some passport numbers were protected with SHA-1.
- The correction was one part of a broader enforcement history involving three breaches, security-program failures and a $52 million multistate settlement. The FTC finalized its order on December 20, 2024.
Marriott’s original disclosure is available at Marriott’s November 30, 2018 announcement. Its correction appears in the April 17, 2024 update.
What Marriott originally claimed
The incident began around July 2014, while Starwood was still a separate company. Marriott completed its acquisition of Starwood in September 2016. Marriott said it received an alert about an attempted database access on September 8, 2018, determined on November 19 that the database had been accessed, and announced the breach on November 30.
The first estimate was an approximate maximum of 500 million guest records, not a verified count of 500 million different people. Marriott later said the upper-limit estimate was about 383 million records and that records could be duplicated, so it could not quantify the exact number of unique guests.
#1 Best Overall
In the 2018 disclosure, Marriott said payment-card numbers and certain passport numbers were encrypted with AES-128. That wording covered particular data categories; it did not mean every field in every record had the same protection.
What changed in April 2024
Marriott said its AES-128 conclusion had been reached during an investigation involving internal and external experts. The company later said it determined that payment-card numbers and some passport numbers were protected with SHA-1 instead. The update did not state that every payment-card number or passport number used SHA-1, nor did it describe the complete storage architecture.
CSO Online reported that Marriott’s attorneys acknowledged during an April 10, 2024 hearing that AES-128 had not been used during the relevant breach period and that the court required a correction within seven days. The report also said the correction was added to an older Marriott breach page rather than issued as a prominent new company-wide announcement. Those procedural details are attributed to the report, not presented as a final finding that Marriott deliberately deceived anyone.
Encryption and hashing are different
| Protection method | How it works | Why the distinction matters here |
|---|---|---|
| AES-128 encryption | Uses a key to transform data into ciphertext that an authorized system can decrypt. | It is the type of reversible protection Marriott originally described. |
| SHA-1 hashing | Transforms input into a digest designed to be one-way rather than routinely reversible. | It is not encryption and is not an equivalent substitute when a system must recover the original value. |
| Unencrypted storage | Leaves the value readable without first reversing a cryptographic transformation. | The FTC separately said 5.25 million passport numbers were unencrypted; that does not establish that all affected fields were plaintext. |
SHA-1’s use does not automatically mean that attackers could immediately read every value. Risk depends on details that have not been fully disclosed publicly, including whether values were salted or keyed, truncated, tokenized, combined with another system, or exposed alongside supporting data. Hashes of guessable values can be attacked with dictionaries, repeated guesses or precomputed tables. Passport numbers are persistent identity documents, while payment-card data may have been represented through tokens, partial values or separate processing systems; the public materials do not resolve those implementation questions.
Rank #3
AES-128 would not, by itself, have prevented an intrusion. Encryption at rest helps only when keys are properly managed and inaccessible to the intruder. Credential theft, excessive access, inadequate monitoring and other controls can still permit a breach or exfiltration.
What information was involved
The FTC said the Starwood incident involved 339 million guest records worldwide. Marriott’s and the FTC’s figures describe records, which may include duplicates, rather than a confirmed count of unique individuals.
Rank #4
Potentially affected information included:
- names, mailing addresses, telephone numbers and email addresses;
- passport numbers;
- Starwood Preferred Guest account information;
- dates of birth and gender;
- arrival and departure details, reservation dates and communication preferences; and
- payment-card numbers and expiration dates for some guests.
The FTC’s consumer guidance describes the categories. The FTC’s October 2024 announcement specifically identified 5.25 million unencrypted passport numbers. “Unencrypted,” “hashed” and “encrypted” are different conditions, so that figure should not be expanded into a claim that every stolen value was readable plaintext.
The wider breach timeline
- July 2014: Unauthorized access to Starwood systems began, according to the FTC.
- September 2016: Marriott completed its acquisition of Starwood and inherited responsibility for the acquired environment.
- September 8, 2018: Marriott received an alert about an attempted access to the Starwood database.
- November 19, 2018: Marriott determined that the database had been accessed.
- November 30, 2018: Marriott publicly disclosed the incident.
- April 10, 2024: CSO Online reported the court hearing at which Marriott’s attorneys acknowledged the AES-128 description was wrong.
- April 17, 2024: Marriott posted its SHA-1 correction.
- October 2024: The FTC announced action covering three breaches between 2014 and 2020, including a later Marriott-network breach that continued from September 2018 through February 2020.
- December 20, 2024: The FTC finalized its order.
What regulators and courts did
FTC order
The FTC said Marriott and Starwood failed to maintain reasonable data-security practices. The final order requires a comprehensive information-security program, annual certification for 20 years, limits on data retention, a U.S. process for customers to request deletion of personal information, and review and restoration of stolen loyalty points when requested. It also prohibits misrepresentations about how the companies protect personal information. Details are in the FTC case record and October 2024 announcement.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
Multistate settlement
Marriott agreed to pay $52 million to 49 states and the District of Columbia and to make cybersecurity improvements, according to the Colorado attorney general’s account. This was a multistate consumer-protection settlement, not a criminal conviction, and it addressed broader security issues than the AES-128 correction alone.
Private litigation
Private cases have raised questions about duties to protect customer information, allegedly misleading privacy statements, arbitration and class-action waivers, causation and proof of injury. A federal court opinion discusses allegations that Marriott’s statements gave customers and investors a misleading impression about the security of acquired Starwood systems. Discussing those allegations is not the same as a final finding that Marriott intentionally lied or that every claimant proved compensable damages.
Does this prove Marriott lied?
It proves that Marriott’s public AES-128 description was inaccurate and that the company later corrected it. It does not, on the cited record, establish what decision-makers knew when the original statement was made or prove intentional deception. Marriott said its initial conclusion came from an investigation and was later revised. The unresolved issue is how the investigation, documentation and public disclosure produced such a material technical error.
Nor does the correction establish that every record was unencrypted, that SHA-1 values were instantly cracked, or that AES-128 would have stopped the breach. Those are separate technical and legal questions.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchQuick Recap
What affected customers should do
- Use a unique password for Marriott Bonvoy and enable available multifactor authentication.
- Watch payment accounts and loyalty accounts for unauthorized activity.
- Treat unexpected breach-related messages as phishing; reach Marriott or a government agency through an official website rather than an email link.
- Consider a credit freeze if passport, address, birth-date or other identity information may have been exposed. A freeze helps block new-credit fraud but does not prevent phishing or misuse of an existing card.
- Do not assume a message is genuine merely because it contains accurate personal details.
What remains unknown
- Which exact fields used SHA-1 and whether the implementation used salt, a key, truncation or tokenization.
- Whether attackers obtained keys, salts, tokens or other supporting systems.
- Why Marriott’s original investigation identified the protection as AES-128.
- How the correction affects particular private claims, including questions of causation and injury.
- Whether the original error was an investigative misunderstanding, a documentation failure or something more serious; the available materials do not resolve intent.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




