Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Marriott International

Marriott International Vendor Cyber Rating & Cyber Score

marriott.com

Marriott International, Inc. is based in Bethesda, Maryland, USA, and encompasses a portfolio of approximately 9,000 properties across more than 30 leading brands in 141 countries and territories. Its heritage can be traced to a root beer stand opened in Washington, D.C., in 1927 by J. Willard and Alice S. Marriott. Marriott International is an equal opportunity employer committed to hiring a diverse workforce and sustaining an inclusive culture. Marriott International does not discriminate on the basis of disability, veteran status or any other basis protected under federal, state or local laws. Community Guidelines: We reserve the right to remove without any notice content that we determine in our sole discretion is offensive or


Marriott International A.I CyberSecurity Scoring

Marriott International
Company Information
Website:http://www.marriott.com
Employees number:213,175
Number of followers:3,181,695
NAICS:7211
Industry Type:Hospitality
Homepage:marriott.com
Marriott International Risk Score (AI oriented)
Between 700 and 749
logo
Marriott InternationalHospitality
Updated:
20/05/2026
707/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Marriott International Global Score (TPRM)
xxxx
logo
Marriott InternationalHospitality
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Marriott International
Marriott InternationalModerate
Current Score
707Ba (MODERATE)
01000
5 incidents
-50 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
714Before Incident
MAY 2026
705Before Incident
APRIL 2026
750Before Incident
Breach
16 Apr 2026Marriott International
Gastrodat and Chekin: Millions of hotel goers may have been exposed after hackers steal data and leak it on Telegram

Massive Data Leak Exposes Nearly 5 Million Hospitality Guests in Spain and Austria

704After Incident
CRITICAL-46
CHEGAS1776335039
Massive Data Leak Exposes Nearly 5 Million Hospitality Guests in Spain and Austria Security researchers at Cybernews uncovered a major data breach involving Spanish and Austrian hospitality platforms, exposing nearly 5 million users’ personal information. The incident stemmed from an attacker who compromised 527 accounts belonging to hotels and hosts, using them to extract sensitive data via automated Python scripts. The stolen data totaling 6.5GB was left unprotected on an open server, allowing researchers to access it. The breach affected platforms like Chekin (a Spain-based automated check-in service) and Gastrodat (an Austrian hotel management software provider), with records pulled from over 170 facilities worldwide. The exposed data includes guest names, email addresses, phone numbers, birth details, ID document numbers, reservation IDs, stay dates, and property addresses. In some cases, internal safety flags and account credentials including JWT tokens were also compromised. Gastrodat alone accounted for 361,000 booking records (11.6 million entries), while Chekin exposed 311,400 records, including 253,000 ID document numbers. The attacker used Telegram to forward the stolen data in real time, though the unsecured server ultimately led to its discovery. The scale of the leak highlights vulnerabilities in hospitality sector security, with millions of travelers and guests now at risk of identity theft and fraud.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Data exfiltration, potential identity theft/fraud
IMPACT
Data Compromised: 6.5GB of personal and reservation dataSystems Affected: Chekin, Gastrodat, and 170+ hospitality facilitiesBrand Reputation Impact: High (hospitality sector vulnerability exposed)Identity Theft Risk: High (ID document numbers, PII exposed)
DATA BREACH
Guest namesEmail addressesPhone numbersBirth detailsID document numbersReservation IDsStay datesProperty addressesInternal safety flagsAccount credentials (JWT tokens)Number Of Records Exposed: Nearly 5 million usersSensitivity Of Data: High (PII, ID documents, credentials)Data Exfiltration: Yes (via Telegram in real time)Personally Identifiable Information: Yes
MARCH 2026
752Before Incident
FEBRUARY 2026
744Before Incident
JANUARY 2026
744Before Incident
DECEMBER 2025
737Before Incident
NOVEMBER 2025
740Before Incident
OCTOBER 2025
791Before Incident
Breach
10 Oct 2025Marriott International
Marriott International Inc.

Marriott International Data Breach Settlement with the City of Chicago

737After Incident
CRITICAL-54
MAR0802208101125
Marriott International Inc. faced a major data breach involving its Starwood-branded hotels, exposing the personal information of up to 383 million guests. The breach, which led to consolidated litigation, included sensitive customer data such as names, addresses, passport numbers, and payment details. The city of Chicago filed claims against Marriott, but the case was dismissed with prejudice after a settlement was reached. The incident underscores the severe consequences of large-scale data leaks, particularly in the hospitality sector, where trust and data security are critical. The breach not only risked financial fraud and identity theft for affected guests but also damaged Marriott’s reputation, leading to legal repercussions and regulatory scrutiny. The scale of the exposure—affecting hundreds of millions—highlights the systemic vulnerabilities in handling customer data across global operations.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Personal information of up to 383 million guestsConsolidated litigation with the city of Chicago (settled)Personal information of guests
DATA BREACH
Personal informationNumber Of Records Exposed: Up to 383 millionHigh (personal information of guests)Yes (guest personal information)
SEPTEMBER 2025
791Before Incident
AUGUST 2025
790Before Incident
JULY 2025
789Before Incident
JUNE 2022
790Before Incident
Breach
01 Jun 2022Marriott International
Marriott International

Marriott International Data Breach

753After Incident
CRITICAL-37
MAR13023722
Hotel giant Marriott International suffered a data breach after an unknown threat actor breached one of its properties and stole 20GB of files. The hackers stole 20GB worth of documents containing non-sensitive internal business files and some credit card information. Marriott hired a third-party security firm to investigate the incident and notified the affected individuals.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Internal business filesCredit card information
DATA BREACH
Internal business filesCredit card informationData Exfiltration: 20GB of files
SEPTEMBER 2019
796Before Incident
Data Leak
01 Sep 2019Marriott International
Marriott International

Marriott International Data Breach

760After Incident
HIGH-36
MAR81730423
Hotel giant Marriott International suffered a data breach after an unknown person gained access to information about certain Marriott associates by accessing the network of an outside vendor formerly used by Marriott. Marriott immediately confirmed that the vendor was taking appropriate to steps to investigate the incident. The vendor reported that it was working with a forensic firm and had notified law enforcement. This incident did not impact the security of Marriott’s internal HR systems or platforms. The information in the document received by this vendor that contains your information includes your name, address, and Social Security number. Marriott hired a third-party security firm to investigate the incident and notified the affected individuals.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
NameAddressSocial Security number
DATA BREACH
Personally Identifiable InformationSensitivity Of Data: HighNameAddressSocial Security number
JUNE 2016
841Before Incident
Breach
16 Jun 2016Marriott International
Marriott International, Inc.

Marriott International (Starwood) Data Breach

767After Incident
CRITICAL-74
MAR019090625
The California Office of the Attorney General disclosed a major data breach at Marriott International, Inc. on November 30, 2018, stemming from an unauthorized access to the Starwood guest reservation database. The breach, which began on or before September 10, 2018, exposed the records of approximately 500 million guests, with 327 million individuals having sensitive personal data compromised. This included names, mailing addresses, email addresses, and encrypted payment card numbers, though the encryption status of the latter was not confirmed to be broken. The incident originated from a vulnerability in Starwood’s systems, which Marriott had acquired in 2016, highlighting a failure in post-merger cybersecurity integration. The breach posed severe risks of identity theft, financial fraud, and reputational damage, given the scale and sensitivity of the exposed data. Regulatory investigations followed, with Marriott facing significant legal and financial repercussions, including fines under GDPR and other data protection laws. The incident underscored critical gaps in third-party risk management and the protection of customer data in large-scale corporate acquisitions.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
NamesAddressesEmail addressesEncrypted payment card numbersStarwood guest reservation databaseBrand Reputation Impact: High (due to scale of breach and sensitive data exposure)Identity Theft Risk: High (due to exposure of PII)Payment Information Risk: Moderate (payment card numbers were encrypted)
DATA BREACH
Personal Identifiable Information (PII)Payment card information (encrypted)Number Of Records Exposed: Up to 500 million (327 million with sensitive details)Sensitivity Of Data: HighData Exfiltration: YesData Encryption: Payment card numbers were encrypted; other data (e.g., names, addresses) likely unencryptedNamesAddressesEmail addresses

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Marriott International ?
?
What was Marriott International's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Marriott International's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Marriott International's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Marriott International's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Marriott International's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Marriott International's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Marriott International's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Marriott International's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Marriott International's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Marriott International's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Marriott International's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Marriott International's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Marriott International ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Marriott International's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?