Marriott / Starwood Data Breach Settlement: Payout Status
Last updated: July 19, 2026
As of 2026, there is no consumer cash settlement in the Marriott/Starwood data breach — no settlement fund, no claim form, and no payout schedule for affected guests. This surprises people, because the breach exposed up to 383 million guest records (Marriott initially estimated 500 million) from the Starwood reservation database between 2014 and 2018. But every resolution to date pays a government body or requires security changes; none pays money to individuals. On June 3, 2025, the Fourth Circuit Court of Appeals decertified the consumer class in Maldini v. Marriott International, ruling that a class-action waiver in the Starwood Preferred Guest terms is enforceable — so consumer claims must be pursued individually, not as a class with a shared fund.
The other Marriott resolutions do not put money in guests' pockets either. The Federal Trade Commission's 2024 settlement is injunctive only — the FTC could not impose a penalty in this case, so there is no consumer redress fund; instead Marriott must let U.S. customers request deletion of their data and must restore stolen loyalty (Bonvoy) points on request. The separate ~$52 million settlement with 49 states and the District of Columbia (announced October 2024) is paid to the states, not to consumers. And the UK regulator's £18.4 million fine went to the UK Information Commissioner's Office. If you were affected, the two concrete things you can actually do are request deletion of your personal data and ask Marriott to review and restore any Bonvoy points stolen through unauthorized access.
Key facts
- Consumer cash settlement
- None as of 2026
- Consumer claim form
- None — no fund to claim
- Class status
- Decertified June 3, 2025 (4th Cir.)
- FTC settlement (2024)
- Deletion + point restoration; $0 to guests
- State AG settlement
- ~$52M — paid to the states
- UK ICO fine
- £18.4 million — paid to UK regulator
- Records exposed
- Up to 383 million (est. 500M)
- Breach disclosed
- November 30, 2018
- Case
- In re Marriott, MDL 2879 (D. Md.)
Official settlement administrator: FTC consumer guidance (ftc.gov)
Who qualifies
- The Starwood reservation database breach affected guests who made reservations at Starwood-brand properties (including W, Westin, Sheraton, Le Méridien, and St. Regis) between roughly 2014 and September 2018 — up to 383 million guest records.
- Exposed data included names, addresses, phone numbers, email addresses, dates of birth, Starwood loyalty account information, arrival and departure details, and for some guests passport numbers (about 5.25 million unencrypted) and payment-card data.
- There is no eligibility test to 'qualify' for a payout, because there is no consumer settlement fund. No court-approved consumer cash settlement has been reached in this matter.
- Any website that tells you to 'file a Marriott claim' for a cash payout, or quotes amounts like '$25 to $75' or '$200 to $50,000,' is not describing a real settlement — those figures are fabricated.
Marriott data breach — what you can actually do now
- 1
Understand there is no consumer settlement check
As of 2026 there is no approved consumer cash settlement and no claim form in the Marriott/Starwood data breach. The consumer class action was decertified by the Fourth Circuit on June 3, 2025, so there is no certified class and no class-wide damages fund. Ignore any site inviting you to file a claim for a payout.
- 2
Request deletion of your personal data
Under the FTC's 2024 order, Marriott must let U.S. customers request deletion of personal information tied to their email address or loyalty account number. You can make this request through Marriott's consumer privacy / individual-rights portal at marriott.com, or by calling Marriott customer service.
- 3
Ask Marriott to restore stolen loyalty points
The FTC order also requires Marriott to review your account on request and restore Bonvoy loyalty points that were stolen through unauthorized access. If you believe points were taken, contact Marriott customer service and ask for a review under the settlement terms.
- 4
Protect your identity — especially if your passport was exposed
About 5.25 million unencrypted passport numbers were exposed. Consider placing a free credit freeze or fraud alert with the three credit bureaus, monitoring your accounts, and — if your passport number was in the breach — watching for identity-related fraud. The U.S. State Department only reissues a passport number if there is evidence of fraud.
- 5
Be skeptical of 'Marriott class action 2026' sites
Several search-optimized sites advertise Marriott payouts and 'how to file' instructions using numbers copied from unrelated data-breach settlements. There is no such Marriott fund, no claim portal, and no payout schedule. Never pay a fee or hand over your Social Security number to 'claim' a Marriott settlement.
- 6
Get alerted when a real settlement opens — ClaimBee
Breach cases can take years, and a consumer fund could still emerge from future litigation. ClaimBee scans 2,000+ cases, matches them to your profile, and alerts you the moment a settlement you qualify for actually opens for claims — so you don't rely on scam sites for the news.
Missed this one? Don't miss the next.
ClaimBee matches your profile against 2,000+ active settlements, shows payout and proof requirements up front, and tracks every deadline for you.
Frequently asked questions
Is there a Marriott data breach settlement payout?
No. As of 2026 there is no consumer cash settlement in the Marriott/Starwood data breach — no settlement fund and no claim form for affected guests. The consumer class action was decertified by the Fourth Circuit in June 2025, the FTC's 2024 settlement pays guests nothing (it provides deletion rights and loyalty-point restoration), and the ~$52 million state settlement is paid to the states, not consumers.
When will I get my Marriott settlement check?
There is no Marriott settlement check for consumers. No court has approved a consumer cash settlement, so no checks are scheduled or being mailed. Any site promising a Marriott data breach payout with a specific dollar amount is not describing a real settlement.
Can I file a claim for the Marriott data breach?
No consumer claim form exists, because there is no consumer settlement fund to claim from. What you can do instead is use Marriott's individual-rights portal to request deletion of your data, and ask Marriott customer service to restore any loyalty points stolen through unauthorized access — both required by the FTC's 2024 order.
What happened to the Marriott class action lawsuit?
On June 3, 2025, the Fourth Circuit Court of Appeals reversed class certification in Maldini v. Marriott International, holding that the Starwood Preferred Guest terms include an enforceable class-action waiver. That means there is no certified consumer class and no class-wide damages fund; remaining claims would have to be pursued by individuals, not as a class.
Where did the $52 million Marriott settlement money go?
To the states. In October 2024, Marriott settled with a coalition of 49 states and the District of Columbia for about $52 million, allocated among those states, plus required security improvements. That money is not distributed to consumers — no part of it becomes a guest payout.
What did the FTC's Marriott settlement do for consumers?
The FTC's 2024 order is injunctive, not monetary — the FTC could not impose a penalty in this case, so there is no consumer redress fund. It requires Marriott to maintain a robust security program, let U.S. customers request deletion of their personal information, and restore loyalty points stolen through unauthorized access. Consumers get rights and protections, not a check.
What was the Marriott / Starwood data breach?
Attackers had access to Starwood's guest reservation database from around 2014 until September 2018 — undetected for about four years — and Marriott disclosed it on November 30, 2018 after acquiring Starwood in 2016. Up to 383 million guest records were exposed (initially estimated at 500 million), including names, contact details, dates of birth, loyalty account data, roughly 5.25 million unencrypted passport numbers, and some encrypted payment-card data.
Related settlements
Closed · Data breach
Equifax 2017 Data Breach $700 Million Settlement
~$6.80–$20,000 (closed) · Closed Jan 22, 2024
Closed · Data breach
Home Depot Data Breach Settlement
Up to $10,000 with proof + free monitoring · Closed Oct 29, 2016
Closed · Data breach
T-Mobile $350 Million Data Breach Settlement
$25 flat ($100 CA) / up to $25,000 · Closed Jan 23, 2023
More settlements people are checking
Payout status for other settlements we track, updated as administrators publish new information.