The Guest Who Never Checked Out
In September 2016, Marriott closed its acquisition of Starwood Hotels & Resorts, folding brands like Sheraton, Westin, and W Hotels into its portfolio and creating the largest hotel company in the world. What Marriott didn’t know at the time was that it had also acquired an intruder. According to Marriott’s own disclosure, attackers had been inside Starwood’s guest reservation database since 2014, two full years before the acquisition even closed.
The intrusion stayed hidden through the entire deal and for two more years after it. It wasn’t until September 8, 2018, that an internal Marriott security tool flagged a suspicious attempt to access the reservation database, using legitimate administrator credentials. Investigators who dug into that alert found a Remote Access Trojan and the credential-theft tool MimiKatz, which together had given the attackers ongoing control of an administrator account. It took Marriott until November 2018 to decrypt what had been taken and understand the scope, and the company went public with the breach on November 30, 2018.
The scale was staggering: up to 500 million guest records, including passport numbers and payment card data. The details of how that data was stored made things worse. Encryption keys for the payment card data were sitting on the same server as the encrypted data itself, and the majority of passport numbers had simply been saved in plain text, not encrypted at all. This wasn’t a sophisticated new attack technique defeating strong defenses. It was a years-old compromise sitting on top of years-old security shortcuts, and it had been there the entire time Marriott’s due diligence team was evaluating the deal.
None of this was Marriott’s doing in the sense that its own engineers didn’t build the vulnerable system. But Marriott inherited it anyway, along with the legal, financial, and reputational exposure that came with it. The breach eventually led to regulatory penalties in multiple jurisdictions and a multistate U.S. settlement of $52 million, on top of Marriott’s own remediation and legal costs. The attacker had already checked in years before the acquisition. Nobody checked the guest list before signing the deal.
Why This Matters If You’re Not a Big Company
It’s easy to read this and think “that’s a Fortune 500 problem.” It isn’t. Small and mid-size businesses acquire other small businesses, get acquired themselves, and merge operations with partners constantly, buying out a competitor, absorbing a smaller shop, combining back-office systems after a merger. The dollar amounts are smaller, but the mechanics are identical: you’re taking on someone else’s IT environment, their vendor relationships, their old software, and whatever has been quietly living in their network, sometimes for years.
The difference is that a company the size of Marriott at least ran some due diligence, and a hidden, well-concealed compromise still slipped through. Most small business deals run none at all. IT and security review rarely make the checklist next to financial audits and contract review, because nobody thinks to ask, or nobody on the deal team knows what to ask. That gap doesn’t get smaller just because the company is smaller. If anything, it gets bigger, because small businesses are less likely to have monitoring in place that would have caught an intrusion in the first place, acquired or not.
What Actually Would Have Stopped This
Real IT due diligence during an acquisition isn’t a box to check, it’s an actual technical review: bringing in someone to look at the target company’s network for signs of existing compromise, not just asking their IT contact if everything is fine. That means checking for unusual administrator activity, unfamiliar remote access tools, unpatched systems, and data that’s stored or encrypted improperly, the exact category of issue that let Marriott’s attackers move payment card data and its encryption keys off the same server for two years without anyone noticing.
It also means treating the acquired environment as untrusted until it’s been reviewed, rather than plugging it straight into your existing network and inheriting whatever risk comes with it. A compromise assessment before close, and continued monitoring immediately after, would have given Marriott a real shot at catching this years earlier than a suspicious database query eventually did on its own.
Security Checklist for Your Business
Treat IT review as a deal requirement. Any acquisition or merger, no matter the size, should include a technical security assessment before you sign, not after.
Assume the target’s network could already be compromised. Have someone actually look for signs of intrusion rather than taking a verbal assurance at face value.
Isolate before you integrate. Keep an acquired company’s systems segmented from yours until they’ve been reviewed and cleaned up, not connected on day one.
Check how sensitive data is actually stored. Encryption only helps if the keys aren’t sitting next to the data they protect, and unencrypted data in the clear defeats the purpose entirely.
Acquisitions move fast, and IT due diligence is one of the easiest things to skip when everyone’s focused on the financials. Marriott’s experience shows how expensive that shortcut can get, even for a company with real resources behind it. MSP Today’s trusted tech partner is JK Computer Solutions. If you want a second set of eyes on your setup, get in touch.
Source: CSO Online, “Marriott data breach FAQ: How did it happen and what was the impact?”.



