The Marriott class action lawsuit over the massive Starwood data breach is effectively over for consumers. In June 2025, the U.S. Court of Appeals for the Fourth Circuit decertified the guest classes and ruled that a class-action waiver in the Starwood Preferred Guest loyalty contract was enforceable, cutting off the path to a class-wide payout.1The Daily Record. Marriott Data Breach Class Action Reversed A separate $52 million settlement reached in October 2024 with 50 state attorneys general and the Federal Trade Commission resolved regulatory claims, but that money went to state governments, not to affected guests.2Massachusetts Attorney General. AG Campbell Announces $52 Million Settlement With Marriott
What the Lawsuit Was About
Hackers broke into the Starwood Hotels reservation network on July 29, 2014.3Office of the Privacy Commissioner of Canada. PIPEDA 2022-005 Investigation Report4Huntress. Marriott Data Breach
The exposed data included names, addresses, phone numbers, email addresses, dates of birth, arrival and departure information, and Starwood Preferred Guest account details. Roughly 5.25 million passport numbers were stored without encryption; another 20.3 million were encrypted. Some payment card numbers and expiration dates were also taken.5Breachsense. Marriott Data Breach Case Study Later analysis put the primary breach at about 383 million unique guest records, with 131.5 million U.S. records specifically identified by state investigators.2Massachusetts Attorney General. AG Campbell Announces $52 Million Settlement With Marriott The FTC later identified two additional breaches, bringing the total affected worldwide to more than 344 million customers across the three incidents.6Federal Trade Commission. FTC Takes Action Against Marriott and Starwood Over Multiple Data Breaches
Consumer lawsuits accused Marriott and Starwood of failing to secure their systems, missing the intrusion for years, and dragging their feet on notification. The cases were consolidated in February 2019 as In re Marriott International, Inc., Customer Data Security Breach Litigation, MDL No. 2879, in the U.S. District Court for the District of Maryland.7JPML. MDL Transfer Order
How the Federal Class Action Ended
Judge Paul W. Grimm certified eight of thirteen proposed guest classes in May 2022, covering an estimated 47.7 million exposed customer records across six bellwether states.8Cohen Milstein. In Re Marriott International Inc. Customer Data Security Breach Litigation Marriott appealed. The Fourth Circuit vacated that ruling and sent the case back so the district court could decide whether a class-action waiver embedded in the Starwood Preferred Guest program contract was enforceable.9Bloomberg Law. Marriott Case Will Affect Class Action Waiver Enforceability
On remand, Judge Grimm recertified the classes in November 2023, finding that Marriott had waived the contractual class-action bar by participating in the MDL in ways inconsistent with it.8Cohen Milstein. In Re Marriott International Inc. Customer Data Security Breach Litigation Marriott appealed again, and this time the Fourth Circuit ended the case rather than sending it back.
In the June 2025 decision, Judge Pamela Harris, writing for the panel, held that the class-action waiver was “valid and enforceable” under New York law, and neither unconscionable nor contrary to public policy. The court said no precedent supported the idea that participating in a multidistrict litigation strips a defendant of the right to invoke such a waiver.1The Daily Record. Marriott Data Breach Class Action Reversed The panel relied on the Supreme Court’s decision in American Express Co. v. Italian Colors Restaurant for the point that class-action waivers can coexist with Rule 23, and it rejected the argument that Marriott had forfeited the defense by pleading it as a “one-line, boilerplate affirmative defense,” finding the issue had been preserved in the answer, the motion to dismiss, and the opposition to class certification.10Ellis & Winters. Terms and Conditions Will Apply: How a Contract Clause Can Kill a Class Claim The panel also rejected narrower “issue classes” that would have resolved only common questions like duty and breach, holding they failed Rule 23’s superiority requirement because individual litigation over injury, causation, and damages would still be needed.11Hogan Lovells. Class Action Waiver Prevails: Fourth Circuit Reverses Certification in Marriott Data Breach
Coverage of the ruling has described it as the likely end of the road for the consolidated class action. As of mid-2025, plaintiffs’ counsel had not said publicly whether they would seek en banc review by the full Fourth Circuit.1The Daily Record. Marriott Data Breach Class Action Reversed
The $52 Million Settlement Does Not Pay Guests
On October 9, 2024, Marriott agreed to pay $52 million to resolve a multistate investigation joined by every state and the District of Columbia. Massachusetts, Connecticut, and Illinois were among the co-leads.2Massachusetts Attorney General. AG Campbell Announces $52 Million Settlement With Marriott12New York Attorney General. Attorney General James Announces $52 Million Multistate Settlement With Marriott13Connecticut Attorney General. Multistate Settlement With Marriott for Data Breach of Starwood Guest Reservation Database None of it is being distributed to affected consumers.
The FTC coordinated with the states and reached a parallel consent order on a 3–0 vote. The agency did not have authority to impose civil penalties in this case, so the entire $52 million moved through the state settlement.6Federal Trade Commission. FTC Takes Action Against Marriott and Starwood Over Multiple Data Breaches
The settlement and consent order require Marriott to make substantial changes to its security practices, including a zero-trust information security program, third-party audits every two years for 20 years, annual certifications to the FTC, data-minimization policies, encryption and access-control requirements, oversight of critical IT vendors, and mandatory security assessments for future acquisitions.13Connecticut Attorney General. Multistate Settlement With Marriott for Data Breach of Starwood Guest Reservation Database Each future violation of the finalized FTC order can carry a civil penalty of up to $51,744.6Federal Trade Commission. FTC Takes Action Against Marriott and Starwood Over Multiple Data Breaches
What Affected Guests Can Actually Do
There is no class-wide check coming, but the FTC consent order created a few concrete rights for U.S. customers whose information was tied to a Marriott or Starwood stay or account. You can request that Marriott delete personal data linked to your email address or loyalty account. You can also ask the company to review your Marriott Bonvoy account for unauthorized activity during the breaches and to restore any loyalty points that were stolen. Marriott is required to offer multi-factor authentication on Bonvoy accounts.6Federal Trade Commission. FTC Takes Action Against Marriott and Starwood Over Multiple Data Breaches
The Fourth Circuit’s decision does not bar guests from pursuing individual claims or mass arbitration, and it is not yet clear whether plaintiffs’ lawyers will attempt en banc review or steer consumers into those alternatives.1The Daily Record. Marriott Data Breach Class Action Reversed For now, the practical answer for the hundreds of millions of people whose data was exposed is that the class-action route has closed, and the remedies available run through Marriott’s contractual data-deletion and loyalty-account processes rather than through a settlement fund.