Marriott settles with FTC, to pay $52 million over data breaches

Share:

Marriott International and its subsidiary Starwood Hotels will pay $52 million and create a comprehensive information security program as part of settlements for data breaches that impacted over 344 million customers.

The settlement requires Marriott and Starwood to implement a comprehensive security program and allow their U.S. customers to request personal data deletions.

Additionally, the American hospitality giant has agreed to pay $52,000,000 to 49 states to resolve claims related to the data breaches.

Marriot’s many data breaches

Marriott International is a hospitality company that manages and franchises a vast portfolio of hotels and lodging facilities, operating more than 7,000 properties across 130 countries.

Starwood was an American hotel and leisure company until its acquisition by Marriott in 2016, making the latter responsible for data security and related hotel operations.

FTC’s announcement highlights three cases where Marriott failed to safeguard its customers’ information.

In June 2014, Starwood suffered a data breach where the payment card information of many of its customers was exposed. The breach was discovered and publicly disclosed 14 months later, leaving impacted clients exposed to elevated risks for over a year.

The second incident concerns hackers accessing 339 million Starwood guest account records, including 5.25 million unencrypted passport numbers. That breach occurred in July 2014 but was detected in September 2018, again leaving clients exposed for a multi-year period.

The third breach impacted Marriott itself, where malicious actors accessed the records of 5.2 million guests in September 2018. The exposed data included names, email addresses, postal addresses, phone numbers, dates of birth, and loyalty account information.

In this case, too, it took Marriott until February 2020 to discover the compromise and inform its clients accordingly.

The settlement

The FTC accuses the two companies of misleading consumers about their data security practices and outlined failures such as poor password controls, outdated software, and lack of appropriate monitoring of its IT environment.

As part of the settlement agreement, Marriott and its subsidiary Starwood will now have to implement the following measures:

  1. Establish a comprehensive information security program with third-party assessments every two years and annual compliance certification for 20 years.
  2. Limit data retention to what is necessary and inform customers of the reason for collecting and keeping their data.
  3. Allow customers to request reviews of unauthorized activity in their loyalty accounts and restore stolen points.
  4. Provide a way for customers to request deletion of personal information linked to their email or loyalty account.
  5. Prohibit misrepresenting how personal data is handled and ensure transparency in security practices.

Marriott has also reached a separate settlement announced simultaneously with 49 states and the District of Columbia, agreeing to pay $52,000,000 to resolve allegations and claims related to the above security incidents.

Bill Toulas

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
8:52 am, Jan 31, 2025
weather icon 5°C
L: 5° | H: 6°
light rain
Humidity: 93 %
Pressure: 1022 mb
Wind: 7 mph SSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0.11 mm
Clouds: 75%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:40 am
Sunset: 4:47 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
5° | 6°°C 1 mm 100% 6 mph 98 % 1028 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
5° | 7°°C 0 mm 0% 8 mph 94 % 1029 mb 0 mm/h
Sun Feb 02 9:00 pm
weather icon
4° | 8°°C 0 mm 0% 8 mph 83 % 1024 mb 0 mm/h
Mon Feb 03 9:00 pm
weather icon
3° | 9°°C 0 mm 0% 8 mph 83 % 1026 mb 0 mm/h
Tue Feb 04 9:00 pm
weather icon
6° | 10°°C 0 mm 0% 11 mph 94 % 1027 mb 0 mm/h
Today 9:00 am
weather icon
5° | 5°°C 1 mm 100% 6 mph 93 % 1022 mb 0 mm/h
Today 12:00 pm
weather icon
6° | 6°°C 0.8 mm 80% 2 mph 92 % 1022 mb 0 mm/h
Today 3:00 pm
weather icon
6° | 7°°C 0 mm 0% 4 mph 88 % 1023 mb 0 mm/h
Today 6:00 pm
weather icon
6° | 6°°C 0 mm 0% 3 mph 93 % 1026 mb 0 mm/h
Today 9:00 pm
weather icon
5° | 5°°C 0 mm 0% 3 mph 98 % 1028 mb 0 mm/h
Tomorrow 12:00 am
weather icon
6° | 6°°C 0 mm 0% 5 mph 94 % 1028 mb 0 mm/h
Tomorrow 3:00 am
weather icon
5° | 5°°C 0 mm 0% 4 mph 94 % 1029 mb 0 mm/h
Tomorrow 6:00 am
weather icon
5° | 5°°C 0 mm 0% 3 mph 90 % 1029 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€100,165.41
-1.12%
Ethereum(ETH)
€3,115.09
1.18%
XRP(XRP)
€2.94
-1.43%
Tether(USDT)
€0.96
-0.01%
Solana(SOL)
€226.24
-2.04%
USDC(USDC)
€0.96
0.00%
Dogecoin(DOGE)
€0.314352
-1.34%
Shiba Inu(SHIB)
€0.000018
0.16%
Pepe(PEPE)
€0.000013
-0.63%
Scroll to Top