LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Marriott International Inc Listed by SilentRansomGroup Ransomware Group

HIGH severityUnverified claimHow we verify

Marriott International Inc Listed by SilentRansomGroup Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·December 13, 2024
Marriott International Inc Listed by SilentRansomGroup Ransomware Group

Reported December 13, 2024.

HIGH
Severity
December 13, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Marriott International Inc was listed by the SilentRansomGroup ransomware group on 13 December 2024 after internal files were exfiltrated in an attack whose timing is not established. Individuals who have stayed at Marriott properties or held accounts with the company should review their personal information and any alerts issued by Marriott.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

For anyone who has stayed at a Marriott property, booked a room through its brands, or worked with the company, the appearance of Marriott International Inc on a ransomware group's leak site raises immediate questions about personal information. Public reporting on 13 December 2024 indicates that SilentRansomGroup claims to have listed the hotel giant after a ransomware attack involving the exfiltration of internal files. The number of people affected remains unknown, and the precise contents of those files have not been detailed in available accounts. What is clear is that any exposure of internal material from a global hospitality operator can create lasting practical risks for guests, employees, and partners whose details may sit inside corporate systems.

This article sets out only what has been reported, places the claim in context, and outlines the concrete steps people can take while fuller details remain limited.

Breaking down the breach

According to public records dated 13 December 2024, Marriott International Inc was listed by the ransomware group SilentRansomGroup. The listing describes the incident as a ransomware attack in which internal files were allegedly exfiltrated. No confirmed figure for the number of people affected has been released, and the exact method of initial access, the duration of the intrusion, and the full scope of systems involved remain undisclosed. The available summary characterises the organisation as one that operates, franchises, and licenses hotels and timeshare properties worldwide, but provides no further technical timeline or confirmed data volume. In short, the public record consists of the group's claim of a successful ransomware operation that included data theft, without independent verification of the scale or the specific files taken.

The group behind it: SilentRansomGroup

SilentRansomGroup is a ransomware operation that has appeared in public threat-intelligence reporting as a group that conducts double-extortion attacks: encrypting systems while also stealing data and threatening to publish it on a dedicated leak site if payment is not made. Like many contemporary ransomware crews, it typically advertises victims on its site to increase pressure, often posting samples or file listings as proof of access. Public knowledge of the group centres on this pattern of claiming corporate victims across multiple sectors and using the threat of data release as leverage. In the present case, the listing of Marriott International Inc is itself a claim made by the group; no independent confirmation that the files were in fact taken or that they match the description has been supplied in the reported facts. Readers should therefore treat the leak-site entry as an unverified assertion until further evidence appears.

Marriott International Inc and its sector

Marriott International Inc is one of the world's largest hospitality companies. It operates, franchises, and licenses hotels and timeshare properties under numerous well-known brands, serving millions of travellers each year across continents. Organisations of this type routinely maintain large volumes of guest reservation data, loyalty-programme records, employee information, supplier contracts, and internal operational documents. The hospitality sector as a whole has become a frequent target for ransomware groups because the combination of high guest volume, payment-card processing, and interconnected property-management systems creates both valuable data and operational pressure points. A breach claim against a company of Marriott's scale is consequential precisely because of the breadth of people and partners who interact with its systems, even when the precise impact remains unconfirmed.

The information in question

The reported facts state only that internal files were exfiltrated in a ransomware attack. No specific categories of personal data—such as names, contact details, payment-card numbers, passport information, or loyalty-account credentials—have been named in the available record. For a hospitality company, internal files could in principle include any combination of guest records, employee files, financial documents, or operational materials, but that remains speculative. Public detail is limited: the exact contents of the exfiltrated material are unconfirmed, and the number of individuals whose information may be involved is listed as unknown. Until more precise disclosures emerge, it is not possible to state with certainty what types of data, if any, have left the organisation's control.

Why it matters

Even when the precise data set is unknown, the real-world risks follow familiar patterns. If guest or employee records were among the internal files, affected individuals could face targeted phishing, identity-fraud attempts, or social-engineering attacks that reference legitimate stay or employment details. Loyalty-programme accounts, if compromised, might be abused for fraudulent bookings or points theft. For the organisation itself, the claim of a ransomware incident can disrupt operations, trigger regulatory scrutiny under data-protection regimes, and erode trust among travellers who expect their reservation information to remain private. Because the number of people affected is unknown and the files are described only as “internal,” the practical consequence for any single person is currently one of heightened caution rather than confirmed harm. The absence of confirmed scale does not eliminate the need for vigilance; it simply means the risk cannot yet be quantified.

What to do if you're exposed

Anyone who has stayed at a Marriott property, held a loyalty membership, or worked with the company should treat the claim as a prompt for basic protective steps. Monitor bank and credit-card statements for unfamiliar charges, enable multi-factor authentication on email and loyalty accounts, and be alert to unexpected messages that reference recent stays or personal details. Consider placing a fraud alert with credit-reporting agencies if you believe sensitive identifiers may have been involved. Because the exact data types remain unconfirmed, these measures are precautionary rather than responses to a verified personal breach. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in other known breach data sets; such a scan provides an additional data point while official details about this incident continue to develop.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyMarriott International Inc security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Marriott International Inc’s full breach history →

More recent breaches

AGT Slots Listed by SilentRansomGroup Ransomware GroupDecember 13, 2024Jacobs Entertainment Inc Listed by SilentRansomGroup Ransomware GroupSeptember 23, 2024Metro Public Adjustment Listed by SilentRansomGroup Ransomware GroupDecember 18, 2024Palomar Insurance Listed by SilentRansomGroup Ransomware GroupDecember 16, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the Marriott International Inc Listed by SilentRansomGroup Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by silentransomgroup — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram