Hospitality has digitised fast on the surface with mobile check-in, dynamic pricing, and digital concierge, but underneath, the software is often a patchwork of acquisitions and legacy systems. When Marriott bought Starwood in 2016, it inherited a reservation system that had been silently breached since 2014. By the time it was discovered, 339 million guest records had been exfiltrated, including passport numbers.
The UK's Information Commissioner's Office fined Marriott £18.4 million, noting that Starwood's legacy systems had lacked adequate security controls for years before the acquisition.1
1 ICO Monetary Penalty Notice, October 2020