Data breach
four-points.marriott.com
- Records
- 52,310
- Breach date
- 6 December 2025Estimated
- Added
- 13 June 2026
What was exposed
2 types of data
- Email addresses52,310
- Phone numbers7,728
About this breach
The investigation team has indexed a breach listing tied to four-points.marriott.com, the web domain for Marriott International's Four Points by Sheraton hotel brand. The listing covers 52,310 records, and the intrusion was claimed by the LockBit 5.0 ransomware group. According to threat intelligence service ransomware.live, the estimated attack date was December 6, 2025, and the listing was discovered the following day. DeXpose, which monitors dark web sources, reported that LockBit 5.0 announced the attack on December 7, 2025, and threatened to publish stolen data unless the company opened negotiations, stating: "The full leak will be published soon, unless a company representative contacts us via the channels provided."
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
December 6, 2025: Estimated date of the attack on four-points.marriott.com, according to ransomware.live.
December 7, 2025: The LockBit 5.0 ransomware group listed the Marriott domain as a victim on its leak site and threatened to publish stolen data, according to DeXpose and ransomware.live.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses and phone numbers. The listing contains 52,310 email addresses in total, along with 7,728 phone numbers.
Not every individual is affected by every type of data listed here.
The indexed records do not include passwords, payment card data, or government identification numbers. However, the full scope of what the attackers exfiltrated has not been independently confirmed, because a detailed company notice has not been located as of September 25, 2026.
What Are the Potential Risks for Affected Individuals?
Email addresses and phone numbers are the raw material for targeted scams. People whose contact details appear in this listing face an elevated risk of phishing messages that pose as Marriott or Four Points communications, fake booking confirmations, loyalty program warnings, or bogus customer service calls. Because attackers can pair an email address with a person's name and travel patterns gleaned from other sources, these scams can be convincing.
The main risks to watch for are:
Phishing emails or texts that reference hotel stays, reservations, or Marriott Bonvoy accounts and try to capture passwords or payment details.
Credential stuffing, if the same email and password combination is reused on other sites.
Smishing, or SMS-based scams, for those whose phone numbers were included.
What Should You Do If You Were Affected?
If you believe your contact details were part of this breach, take these practical steps:
Check whether your email address appears in this breach using the search tool.
Change passwords on any Marriott or Four Points accounts, and change the password anywhere else you reused the same one. Use a unique password for each account.
Turn on multi-factor authentication wherever it is offered, especially for email, banking, and travel accounts.
Treat unexpected messages about reservations, loyalty points, or account problems with suspicion. Go to the company's website directly rather than clicking links in emails or texts.
Watch your bank and credit card statements for unfamiliar charges, and consider a credit monitoring service if your details were exposed alongside financial information elsewhere.
In the news
- ransomware.live victim listing for four-points.marriott.comransomware.live (opens in a new tab)
- DeXpose: LockBit 5.0 Targets Marriott Internationaldexpose.io (opens in a new tab)
- HookPhish: Ransomware group lockbit5 hits four-points.marriott.comhookphish.com (opens in a new tab)
- BreachSense: Four Points by Sheraton Data Breach in 2025breachsense.com (opens in a new tab)
