Desk live·
ForensicPost
Breaches/Hospitality/File 22-0705

Marriott Says Social Engineering of One Employee Exposed 20GB and About 400 People

A threat actor talked a single Marriott associate into giving up access to their computer, held it for about six hours, and left with 20GB. Around 400 people were notified — the smallest affected count in this database.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetMarriott International
ActorUnattributed
S. Rosler10 min readConfidence: high2 sources reviewed

Marriott confirmed in July 2022 that a threat actor had used social engineering to persuade one associate at a single property — reported as the BWI Airport Marriott in Maryland — to provide access to that associate’s computer. Access to the one device lasted approximately six hours. Around 20GB of data was taken.

Marriott stated that the majority was non-sensitive internal business files relating to the operation of the property, and notified roughly 400 individuals. The company said it had identified and was investigating the incident before the actor made contact with an extortion demand, which was not paid. Reporting described this as Marriott’s third breach since 2018.

The Smallest File Here Has The Same Shape As The Largest

Four hundred people is negligible against the 14.7 million at 23-1031 or the billion at 22-0630. The desk files it anyway, and grades it SEV 2, because the technique is indistinguishable.

One person persuaded to grant access is exactly what happened at 22-0120, 22-0808 and 22-0915, and in those cases it reached an identity provider, a communications platform and a global ride-hailing company. What differed was not the method or the defence. It was which desk the person happened to be sitting at.

Six Hours Is Not A Small Window

The corpus routinely records dwell measured in months — 425 days at 23-0808b, nine and a half years of exposure at 23-0512. Six hours reads as a containment success.

Twenty gigabytes left in those six hours. The desk records dwell time because it is the field organisations publish, and this file is the reminder that it correlates poorly with what was taken. Exfiltration is bounded by bandwidth, not by patience.

Detected Before The Demand

Marriott says it found and was working the incident before the extortion contact arrived. That ordering is uncommon in this corpus and worth crediting.

It records the opposite ordering repeatedly: at 22-1104b the scale arrived three months later from the attacker, at 23-1110 the entry route did. An organisation that learns what happened from the person who did it has no independent account to offer anyone.

How we reported this

Compiled from Marriott’s statements and contemporaneous reporting, listed below. Claims made about the contents of the stolen data originated in part with the actor and are not adopted here. The count of prior Marriott breaches is as reported and this desk has not independently enumerated them; the separate incident involving a hotel technology provider is filed at 25-0123b. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Marriott confirms another data breach after hotel got hackedBleepingComputer
  2. Marriott Confirms Small-Scale Data BreachSecurityWeek
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary