The alert that ended it was almost nothing. On 8 September 2018 a monitoring tool watching the Starwood guest reservation database — a system run for Marriott by the contractor Accenture — flagged a single unusual query from an administrator's account: a request for the number of rows in a table. Automated processes do not generally ask that question. People do. Marriott's chief executive, Arne Sorenson, later told the United States Senate in written testimony that the administrator whose credentials had been used had not run the query. Investigators followed the alert inwards and found a remote access trojan already resident on the network, alongside Mimikatz, the utility that scrapes usernames and passwords out of memory.
Three dates matter in this story and are routinely collapsed into one. The intrusion into Starwood's network began in 2014. Detection came on 8 September 2018. Public disclosure came on 30 November 2018, and the eighty-three days between the second and the third are explained by 19 November, when investigators finally decrypted two files the intruders had staged for removal — one an export of a table from the guest reservation database, the other an export of a table holding passport information. Only at that point did Marriott know what had left the building. It announced eleven days later, on a Friday morning, that the records of up to approximately 500 million guests may have been reached, and set up a notification site and a call centre the same day.
For roughly 327 million of those guests, Marriott said, the exposed information included some combination of name, mailing address, telephone number, email address, passport number, date of birth, gender and stay details. Payment card numbers had been encrypted with AES-128, and the company added that it could not rule out that both components needed to decrypt them had been taken. On 4 January 2019 it corrected the arithmetic in a way most summaries still get wrong: approximately 383 million was an upper limit on guest records, not on distinct guests, and Marriott said it could not quantify the smaller real number. The same update disclosed 5.25 million unencrypted passport numbers alongside 20.3 million encrypted ones, and 8.6 million encrypted payment cards, all but roughly 354,000 already expired.
The uncomfortable part was the calendar. The intrusion began in 2014; Marriott completed its purchase of Starwood in September 2016. It had not been breached so much as bought a network already occupied, then run it for two more years unaware. Attribution arrived as journalism rather than as a government finding: in December the New York Times and Reuters, citing unnamed officials briefed on the inquiry, linked it to hackers working for China's Ministry of State Security. China's foreign ministry rejected the reports, saying it opposed all forms of cyber theft, and Marriott itself has never named an attacker. Regulation came slower. The UK Information Commissioner announced an intended fine of £99,200,396 in July 2019, settling on £18.4 million on 30 October 2020 — reaching only conduct after the GDPR took effect on 25 May 2018, a few months out of four years, and faulting Marriott for failing to monitor privileged accounts.
The Postal Service's open window
On 21 November 2018 the security journalist Brian Krebs reported that the United States Postal Service had just closed a weakness in the API behind Informed Visibility, the service that lets bulk mailers track campaigns in near real time. There was no exploit and no intrusion involved. Any of the roughly 60 million people holding a usps.com account could query the interface for other users' details — email addresses, usernames, user IDs, account numbers, street addresses, telephone numbers, mailing campaign data — and because the API accepted wildcard parameters, a single request could return an entire data set rather than a single record. It also appeared to permit requests to change other users' account details. What made it a story rather than a bug was the calendar: an independent researcher said he had reported it to USPS more than a year earlier and never received a reply, and it was fixed within days of a journalist asking about it on his behalf. USPS said it had no information that the weakness had been used against customer records.
American cyber defence gets an agency
Ten days after the midterm elections, on 16 November 2018, the Cybersecurity and Infrastructure Security Agency Act was signed into law as Public Law 115-278, converting the Department of Homeland Security's National Protection and Programs Directorate — a name that had never once helped anyone understand what it did — into a standalone operational agency with divisions for cybersecurity, infrastructure security and emergency communications. The bill had taken eleven months: the House passed it in December 2017, the Senate by unanimous consent on 3 October 2018, the House again on 13 November. CISA formally stood up on 26 November. Christopher Krebs became its first director on the day the law was signed, eighteen months after the WannaCry weekend had shown what an unpatched public network looks like from inside. He was dismissed on 17 November 2020, two years to the week after taking the post, having publicly rejected claims that the presidential election had been compromised. By early 2026, after a restructuring begun in January 2025 and a funding lapse, the agency was reported to have lost more than a third of the staff it held that January.
Switching off eKYC
India spent November 2018 dismantling the most efficient identity check it had ever built. The Supreme Court's Aadhaar judgment of 26 September 2018 struck down Section 57 of the Aadhaar Act, removing the legal basis on which private companies had been running Aadhaar-based electronic know-your-customer checks. The Department of Telecommunications issued detailed instructions on 26 October ordering operators to stop using Aadhaar authentication both for new connections and for re-verifying existing subscribers, and to report compliance by 5 November. On 6 November it set out the replacement: a live photograph of the subscriber taken at the point of sale, photographs of the original proof-of-identity and proof-of-address documents, every image watermarked with the customer acquisition form number, GPS coordinates, the outlet's name and code and a date-and-time stamp, a one-time password sent to an alternate number, and a ceiling of two connections a day against any single document.
Nothing was stolen; that is the reason to record it. The largest Indian security story of the month was a country switching off a system that worked, because a court had found no law authorising private parties to use it. An industry that had rebuilt customer onboarding around a thirty-second biometric check had a fortnight to return to photographs and paperwork; operators asked to keep using Aadhaar eKYC until 20 November while they stood the new process up. It landed on top of the Reserve Bank's payment data localisation deadline of 15 October, which the largest card networks had missed. Parliament restored a voluntary, consent-based route for banks and telecom operators in 2019, and the statutory privacy framework that should have preceded all of it — the DPDP Act — was still five years away.
AI, category two of fourteen
On 19 November 2018 the Commerce Department's Bureau of Industry and Security published an advance notice of proposed rulemaking in the Federal Register, asking how the emerging technologies essential to American national security ought to be defined. Nothing was controlled that day; it was a request for comment, carrying a representative list of fourteen technology categories with artificial intelligence and machine learning second among them. It is the paperwork from which the later export rules on AI chips descend. A week afterwards, at re:Invent in Las Vegas from 26 to 30 November, Amazon Web Services answered the commercial question instead: Andy Jassy's keynote on 28 November unveiled Inferentia, an inference chip of Amazon's own design, alongside SageMaker Ground Truth for labelling training data, Textract, Personalize and Forecast. Earlier, on 13 November, DeepMind said the team behind its Streams app would move to Google; critics read it as breaking a pledge that DeepMind's health data would never be connected to Google accounts, and the company said nothing was changing. Its UK independent review panel was disbanded the following year.
BlackBerry buys the AI antivirus
On 16 November 2018 BlackBerry agreed to buy Cylance for $1.4 billion in cash, plus the assumption of unvested employee incentive awards — its largest acquisition, and the moment the loudest machine-learning endpoint challenger stopped being independent. Cylance had built its business on the argument that a trained model could stop malware it had never seen, and that signature files were an obsolete habit; BlackBerry folded it into the Spark platform it was assembling. The deal closed on 21 February 2019. Six years later BlackBerry sold the Cylance assets to Arctic Wolf for $160 million and a block of shares, completing on 3 February 2025. On 13 November Kaspersky had opened its first Transparency Centre in Zurich and begun processing European users' threat data in Swiss data centres — its answer to years of Western distrust and to allegations of Russian government ties that it denies. On 30 November the DC Circuit Court of Appeals upheld the American government's ban on its software anyway, and in 2024 the Commerce Department barred the company from selling to American customers at all.
⏳ Time capsule — November 2018
- The Camp Fire started in Butte County, California, on 8 November and destroyed most of the town of Paradise; it remains the deadliest and most destructive wildfire in the state's history.
- Around seventy heads of state and government gathered in Paris on 11 November for the centenary of the armistice that ended the First World War.
- Stan Lee, the Marvel Comics writer and editor, died on 12 November at the age of 95.
- NASA's InSight lander touched down on Elysium Planitia on 26 November — the agency's first Mars landing since Curiosity in 2012.
The month acquisitions got a security price
The four years are what everyone remembers, but the enforcement is what changed practice. The Information Commissioner's £18.4 million reached only the sliver of the intrusion that fell after the GDPR commenced, and one of its findings was that Marriott had not encrypted passport numbers — the field that made this breach unlike every other hotel breach, because a passport number is not reissued when it leaks. On 9 October 2024 the Federal Trade Commission and a coalition of state attorneys general closed their own investigations: a $52 million payment to the states, and an order requiring Marriott to run a documented security programme, to give US customers a route to have their data deleted, and, in plain terms, to carry out security due diligence on future acquisitions.
No one has ever been charged for the intrusion itself. The February 2020 indictment of four members of China's People's Liberation Army over Equifax was announced alongside references to Marriott and OPM as part of a single pattern of state data collection, but it charged neither, and the Starwood case has stayed where December 2018's reporting left it — attributed by unnamed officials, never tested in a courtroom. What survives is the question every acquirer now has to answer before signing, and the fact underneath it: a company can be compromised for two years before it is bought and two more after, and the alert that finally catches it will be a request for a row count. The Vault continues backwards from here.