D-Secure - Advanced Data Security Solutions
Resources & BlogsPartnersSupport
Login
D-Secure - Advanced Data Security Solutions

Leading provider of Compliant data erasure solutions for enterprises worldwide. Secure your data lifecycle with our enterprise-grade security solutions.

Products
  • All Products
  • Drive Eraser
  • Drive Eraser Diagnostic
  • File Eraser
Industries
  • All Industries
  • Healthcare
  • Banking & Finance
  • Government
  • Education
  • Non-Profit
Resources
  • Documentation
  • Compliance
  • Blog
  • Case Studies
  • NIST 800-88 Checker
  • ROI Calculator
Company
  • About Us
  • Contact
  • Company Profile
  • Partners

© 2026 D-Secure Technologies Pvt. Ltd. All rights reserved.

All systems operational
Privacy PolicyLegal PolicyTerms of ServiceEULACookie Policy
M&A Security & Compliance Case Study

Marriott Bought a Hotel Chain. It Also Bought a Breach That Had Already Been Running for Two Years.

By D-Secure Editorial TeamSeptember 07, 2026 9 min read

M&A due diligence checklists have entire sections for financials, culture, and legal exposure. Almost none of them have a real answer to a much simpler question: what's actually still running on the servers we just acquired — and has anyone ever properly erased what came before them?

Marriott Starwood M&A Data Breach Case Study - Legacy System Erasure Gap

In September 2016, Marriott International closed one of the largest hotel acquisitions in history, absorbing Starwood Hotels & Resorts and, with it, eleven new brands, hundreds of thousands of employees, and a reservation system that had been quietly compromised by an unknown intruder since 2014 — two full years before Marriott ever signed the deal. Nobody involved in the acquisition knew it at the time. The breach sat there, undiscovered, through the entire due diligence process, through the deal closing, and through nearly two more years of Marriott running Starwood's legacy IT infrastructure largely as-is. Full technical integration of an acquisition that size takes time, and Starwood's reservation system was one of the pieces Marriott hadn't gotten around to replacing yet.

Marriott finally discovered the intrusion in September 2018, when an internal security tool flagged unusual database activity. By the time the investigation wrapped, the numbers were staggering: roughly 500 million guest records exposed, including passport numbers for 327 million individuals, spanning reservation data that had been sitting on that legacy system the entire time.

The UK's Information Commissioner's Office (ICO) opened an investigation, initially signaling an intent to fine Marriott £99.2 million — later adjusted to £18.4 million after representations, but still one of the largest GDPR enforcement actions of its era. And the regulator's reasoning is the single most important detail in this entire story: the ICO wasn't primarily punishing Marriott for what happened on Starwood's watch before the acquisition. It was punishing Marriott for what happened after the deal closed — specifically, for continuing to run legacy Starwood infrastructure without adequately assessing what was on it, securing it, or replacing it, for roughly two years after inheriting it.

The Regulator's Precedent on M&A Due Diligence

Marriott's own defense was that "acquisition due diligence is not a seemingly endless process" — an understandable position from a company that had just absorbed an entire competitor's global IT footprint overnight.

The regulator's verdict: That may be true, but the legal obligation to know what data you are responsible for, and to protect or sanitize it, does not expire simply because an integration project is complicated.

Quick Gut Check Before We Go Further

If your organization has acquired another company in the last two years, could anyone on your IT, compliance, or security team tell you, right now, exactly which of the acquired company's servers, databases, and employee laptops are still running on old infrastructure that has never been properly audited, sanitized, or decommissioned?

The Two Kinds of Legacy Risk Hiding Inside Every Acquisition

It's worth separating this problem into two distinct risks, because they get treated as one issue in most standard M&A playbooks, even though they operate on completely different timelines.

1. Inherited Exposure

The Marriott scenario: data, active backdoors, or dormant vulnerabilities that already existed inside the target company before the deal closed. The acquirer now owns them legally and operationally.

  • • 75% of executives report an undisclosed breach is reason enough to walk away from a deal.
  • • 40%+ of manufacturing M&A deals experienced incidents traceable directly to inherited legacy systems.

2. Integration Debt

The quieter, slower risk created after the deal closes. Redundant servers, duplicate SaaS tools, and orphaned storage units that pile up when nobody finishes the unglamorous work of sanitizing and retiring what's obsolete.

  • • Zombie Systems: Running silently, holding historical PII, consuming budget, but completely unmanaged.
  • • Often discovered only during regulatory audits or secondary ransomware intrusions.

Both risks point at the same underlying gap: M&A due diligence and post-merger integration planning are built around financial models, legal structure, culture, and synergy milestones. Data disposition — figuring out what old systems and hardware need to be sanitized, verified, or destroyed — sits at the very bottom of the checklist, if it appears at all.

Why This Gap Survives Even at Careful, Well-Run Companies

It would be easy to read the Marriott case as a story about corporate carelessness. It isn't. Marriott is a sophisticated, well-resourced global enterprise. The gap didn't come from indifference — it came from the structural mismatch between how M&A timelines work and how deep technical security audits must go.

Due diligence occurs under intense time constraints and confidentiality restrictions. A buyer cannot dispatch a team to audit every server rack or employee laptop closet before signing. Consequently, true technical reality only emerges after the ink is dry — precisely when leadership attention pivots to organizational restructuring, brand consolidation, and customer retention. Decommissioning legacy servers becomes an item for "Phase Two," and in many companies, Phase Two never actually arrives.

The Multi-Department Orphan Problem

Legal DepartmentOwns deal contracts, indemnities, and regulatory disclosures — not physical storage sanitization.
IT OperationsPrioritizes keeping services live during migration, not securely erasing redundant hardware.
Security / SecOpsMonitors active threats on production infrastructure, rarely auditing disconnected legacy assets.
Corporate ComplianceDefines data retention policies, but lacks tools to verify serial-number-level erasure on site.

Result: Each department handles its slice competently, yet the holistic task of "find every inherited system and verify standardized erasure" belongs to everyone collectively and to no one individually.

The Compliance Layer Doesn't Pause for Integration Timelines

Global data privacy regulators have made it clear: they do not grade on a curve for corporate complexity. Under GDPR Article 5(1)(f) (integrity and confidentiality) and Article 32 (security of processing), an organization is held strictly accountable for any data it retains, regardless of whether that data was collected organically or absorbed through a corporate acquisition closed eighteen months earlier.

This pattern is not isolated to hospitality. The 2022 merger bringing Change Healthcare into UnitedHealth Group's ecosystem was followed by a catastrophic ransomware event affecting over 100 million individuals, in an environment where complex, multi-entity legacy IT integrations formed the backdrop. Frameworks like the HIPAA Security Rule,FTC Safeguards Rule, and banking regulations enforce the exact same standard: there is no regulatory exemption for "we are still integrating."

The Divestiture Mirror Image: Transition Services Agreements (TSAs)

The same vulnerability emerges in reverse when an organization spins off a subsidiary or sells a business division. Divestitures typically rely on Transition Services Agreements (TSAs), where the seller provides shared IT infrastructure for 6 to 24 months while the buyer builds independent capacity.

This in-between period is where severe compliance cracks form:

  • Temporary shared servers get extended indefinitely past original contract deadlines.
  • Customer records of the divested unit linger on physical drives retained by the parent company.
  • Neither party can definitively prove who holds custody of historical data or whether residual backups were sanitized.

When a data incident occurs during or after a TSA period, "the transition was still underway" does not satisfy regulatory inquiries. A TSA without verified, tamper-proof erasure records is simply an open invitation to litigation.

Try This Right Now (Two Minutes)

If your company completed an acquisition, merger, or major divestiture in the past 24 months, ask your IT leadership these three questions:

1.

Ask for a current, comprehensive inventory of every server, database, and laptop inherited from the acquired entity — an actual serial-tracked list, not a ballpark estimate.

2.

Ask how many of those systems have undergone formal data sanitization or security assessments since deal close, versus how many are running simply because nobody turned them off.

3.

Ask whether there is a dated decommissioning schedule with verified erasure records, or if "we will get to it during phase two" is the working plan.

If question three produces a shrug, you have pinpointed the exact vulnerability that resulted in Marriott's £18.4 million regulatory fine.

Would Your Organization Survive This Exact Audit?

Review these 4 criteria with your integration director, IT asset manager, and data protection officer:

Do you have a complete, serialized inventory of every device and server inherited — including retired assets in storage closets?
Has every inherited storage medium been individually sanitized or audited, rather than assumed safe because 'it worked fine before'?
Is there a dated decommissioning roadmap with an accountable owner for each redundant legacy workload?
Do you possess audit-ready, cryptographically signed erasure reports for all decommissioned equipment matching NIST 800-88 standards?
4 'Yes' Answers

Exemplary posture. Your integration program is far ahead of standard industry averages.

2–3 'Yes' Answers

Actionable gaps exist in tracking and retiring inherited infrastructure. Decommissioning plan required.

0–1 'Yes' Answers

Critical inherited risk. Your company is likely harboring unmonitored zombie systems holding sensitive customer data.

What an M&A Data Disposition Program Actually Requires

To eliminate the legacy system erasure gap permanently, forward-thinking enterprises deploy a structured 7-pillar framework:

01

Build a Full Inherited-Asset Inventory Within 90 Days

Treat inventory creation as an independent workstream with its own hard deadline, cataloging every acquired server, laptop, and data volume.

02

Assign a Single Accountable Owner for Legacy Disposition

Separate operational uptime goals from decommissioning duties. The engineer tasked with keeping systems running cannot be the sole champion for turning them off.

03

Treat Every Inherited System as Untrusted by Default

Apply the same zero-trust validation to legacy systems that you would apply to an unverified third-party appliance.

04

Establish Fixed Decommissioning Milestones

Replace open-ended 'during integration' milestones with contractual retirement dates to prevent zombie systems from lingering for years.

05

Demand Audit-Ready, Serial-Number-Level Erasure Records

Ensure every retired drive, SSD, or virtual instance is purged using software compliant with NIST 800-88 Rev. 1/2 or IEEE 2883-2022, generating tamper-proof audit trails.

06

Maintain Security Monitoring on Dormant Systems

Dormant legacy databases are high-value targets. Maintain active threat telemetry until the final sanitization certificate is generated.

07

Embed Data Disposition Directly into the M&A Playbook

Integrate secure sanitization protocols into deal milestones alongside legal reviews, tax structure, and HR integration.

The Key Takeaway

The core lesson of the Marriott breach is not that M&A is inherently perilous or that due diligence must be infinite. The lesson is simpler and more operational: regulatory accountability does not pause while you integrate. Every day an unassessed legacy server stays connected, legal liability compounds.

Every corporate deal brings home more than financial balance sheets and intellectual property. It brings home someone else's old servers, outdated endpoints, and untracked databases. Organizations that avoid becoming headline case studies are those that pair deal closing with an automated, verified data erasure pipeline.

Enterprise Solution

Eliminate M&A Legacy Blind Spots

DSecureTech Drive Eraser and File Eraser automate data sanitization across inherited data centers, servers, and employee endpoints — producing tamper-proof, auditable certificates for every serialized asset.

Explore Drive Eraser

Related Guides & Case Studies

  • Major Bank Fined $60M for Decommissioning Failures
  • ITAD, Secure Erasure & Scope 3 Reporting
  • Secure IT Asset Disposal for ITAM Teams
  • Maintaining Tamper-Proof Chain of Custody
  • Forensic Preservation vs Secure Laptop Erasure

Planning an Acquisition or Decommissioning?

Speak with our data sanitization engineers to design a standards-compliant erasure workflow for inherited infrastructure.

Contact Our Security Specialists

Close the Legacy Erasure Gap in Your Next M&A Transaction

Transform "we'll get to it during integration" into automated, verifiable, serialized erasure reports that satisfy global privacy regulators.

Schedule an M&A Sanitization AuditView Licensing & Plans

Solutions for Compliance

Explore the full D-Secure data security suite

Drive EraserNIST 800-88 compliant HDD & SSD secure erasure
Drive VerifierPost-erasure verification — confirm zero data traces
File EraserSecure file & folder shredding beyond Recycle Bin
Expert Solution

How Do Experts Handle This?

Enterprise-grade data sanitization requires more than just standard deletion. Experts use professional software like Drive Eraser to ensure 100% data destruction across all media types.

Standard Compliance

Meeting NIST 800-88 and GDPR standards with full audit trails.

Enterprise Ready

Scalable solutions for ITAD partners and large organizations.

Get Expert Consultation

Securing Data Everywhere

Trusted by global enterprises for zero-leakage data sanitization.

100%
Verified
0
Leaks
24/7
Support

Related Articles

View All Blog Posts
Data Erasure

Enterprise Data Erasure Compliance Guide | D-Secure

By Prashant SainiAugust 24, 2026
Standards

NIST SP 800-88 Rev. 2 (Final, September 2025) — Official Media Sanitization Guidelines Explained

By Prashant SainiJuly 17, 2026
Government

Government IT Disposal Requirements

By Nitesh KushwahaJanuary 11, 2026

Frequently Asked Questions

The ICO clarified that Marriott was not primarily penalized for the pre-acquisition intrusion under Starwood's watch. Rather, the penalty was imposed for post-acquisition negligence: Marriott continued operating Starwood's legacy reservation systems for roughly two years without conducting adequate technical security assessments, maintaining proper asset oversight, or decommissioning unneeded systems holding 500 million guest records.
Inherited exposure refers to dormant malware, prior breaches, or existing software vulnerabilities already present inside the target company before closing. Integration debt refers to the operational and security backlog created after closing—redundant servers, duplicate applications, and orphaned storage devices that linger indefinitely because retiring and sanitizing legacy IT assets takes lower priority than business consolidation.
Zombie systems are legacy servers, databases, or applications that remain powered on and connected to enterprise networks, holding historical customer records or intellectual property, but have no active business owner or monitoring. Because nobody actively uses or patches them, they become prime targets for ransomware gangs and unauthorized access.
Under a TSA, a parent company temporarily hosts systems for a divested business unit. Gaps arise when shared systems are extended past contractual deadlines, customer data from the sold division lingers on parent hardware, or employee permissions remain unsegregated. Without standardized data separation and verifiable erasure, both parties face severe regulatory exposure under GDPR, HIPAA, and FTC rules.
D-Secure Drive Eraser and File Eraser provide automated, high-speed data sanitization across servers, loose storage drives, NVMe SSDs, and employee laptops in full compliance with NIST SP 800-88 Rev. 2 and IEEE 2883-2022. Each sanitized asset generates a digitally signed, tamper-proof Certificate of Erasure with serial-number tracking, providing irrefutable audit trails for regulators, compliance boards, and M&A integration teams.

Comments (0)

Your email address will not be published. Providing an email is optional.

No comments yet. Be the first to comment.

Have Questions About This Topic?

Send us an enquiry regarding: Marriott Bought a Hotel Chain. It Also Bought a Breach That Had Already Been Running for Two Years.

Select Country
Select Business Type
AI Documentation and Project Summary