The Marriott Breach: What to do if Your Information Has Been Compromised
Privacy, Cyber & AI Decoded Alert | 1 min read
Dec 21, 2018
Risk Management Question
Are you one of 500 million guests whose personal and financial information was compromised in the recent breach of Marriott's guest reservation system?
The Issue
Marriott's guest reservation system may have compromised data including passport numbers, credit card numbers, email addresses, phone numbers, DOB, and arrival and departure information of not only Marriott guests, but also guests of the entire Starwood chain (think: major hotel names like Westin and Sheraton, among others). If you have stayed at the Marriott or any of the Starwood chain hotels within the past four years, it is likely your information has been compromised.
Risk Management Solution
If you have been a Marriott guest during this time period, assume your business and personal email accounts have been compromised, and be on the lookout for travel-related emails with detailed information about you and your family members. Follow our anti-phishing rules for any email you receive:
- Don't click on links in any electronic communications from Marriott or any Starwood chain hotel. If you must click, first call the hotel and confirm they sent it.
- Don't respond to voicemail messages, robo calls, or text messages from any Marriott or Starwood chain hotel. Don't call the number back. Instead, research the correct phone number and call the hotel or reservation system and confirm that they called you. The legitimate caller will not request any password by phone or email.
- Don't fall for a hacker's phishing email to provide any offers that sound too good to be true, such as: "We're sorry. Here is a free 2-night stay at any Marriott location."
- Closely monitor your credit cards to assess any suspicious activity.
- Change your passwords to any affected—or even unrelated—account.
- Consider signing up for Marriott's free WebWatcher enrollment.
As always, think before you click.
Related People
Related Capabilities
Featured Insights

Hinshaw Alert
Apr 17, 2026
Q&A: How to Submit Your IEEPA Refund Claim as CAPE Portal Launches April 20, 2026

Webinar
Apr 29, 2026
When a Cyber Breach Hits: Cybersecurity, Privacy, and Compliance

Event
Apr 23, 2026
Driving Ahead: Insights from Industry Leaders Auto Finance Seminar

Press Release
Apr 17, 2026
André Sesler Elected to the Board of Trustees of the University of Florida Law Center Association

In The News
Apr 14, 2026
Bloomberg Law Recaps Panels Presented at Hinshaw's 25th Anniversary LMRM Conference

In The News
Apr 14, 2026
Michael Dowell Discusses the Uncertain Impact of Growing Medicare Advantage Scrutiny

Privacy, Cyber & AI Decoded Alert
Apr 9, 2026
6 Key Takeaways From the IAPP 2026 Global Summit for Privacy Compliance Professionals

In The News
Apr 9, 2026
Megan Lopp Mathias Discusses Future of DEI Employment Initiatives

Consumer Crossroads: Where Financial Services and Litigation Intersect
Apr 8, 2026
After Arbitration, Does a District Court Have Jurisdiction to Confirm or Vacate an FAA Award?



