Marriott settles with the FTC for $52 million over data breaches

Marriott International has agreed to pay $52 million and make changes to bolster its data security to resolve state and federal claims related to major data breaches that affected more than 300 million of its customers worldwide.

The Federal Trade Commission and a group of attorneys general from 49 states and the District of Columbia announced the terms of separate settlements with Marriott on Wednesday. The FTC and the states ran parallel investigations into three data breaches, which took place between 2014 and 2020.

As a result of the data breaches, “malicious actors” obtained the passport information, payment card numbers, loyalty numbers, dates of birth, email addresses and/or personal information from hundreds of millions of consumers, according to the FTC’s proposed complaint.

The FTC claimed that Marriott and subsidiary Starwood Hotels & Resorts Worldwide’s poor data security practices led to the breaches.

Specifically, the agency alleged that the hotel operator failed to secure its computer system with appropriate password controls, network monitoring or other practices to safeguard data.

As part of its proposed settlement with the FTC, Marriott agreed to “implement a robust information security program” and provide all of its U.S. customers with a way to request that any personal information associated with their email address or loyalty rewards account number be deleted.

Marriott also settled similar claims brought by the group of attorneys general. In addition to agreeing to strengthen its data security practices, the hotel operator also will pay $52 million penalty to be split by the states.

In a statement on its website Wednesday, Bethesda, Maryland-based Marriott noted that it made no admission of liability as part of its agreements with the FTC and states. It also said it has already put in place data privacy and information security enhancements.

In early 2020, Marriott noticed that an unexpected amount of guest information was accessed using login credentials of two employees at a franchised property. At the time, the company estimated that the personal data of about 5.2. million guests worldwide might have been affected.

In November 2018, Marriott announced a massive data breach in which hackers accessed information on as many as 383 million guests. In that case, Marriott said unencrypted passport numbers for at least 5.25 million guests were accessed, as well as credit card information for 8.6 million guests. The affected hotel brands were operated by Starwood before it was acquired by Marriott in 2016.

The FBI led the investigation of that data theft, and investigators suspected the hackers were working on behalf of the Chinese Ministry of State Security, the rough equivalent of the CIA.

—Alex Veiga, AP Business Writer

https://www.fastcompany.com/91207103/52-million-settlement-announced-between-marriott-ftc?partner=rss&utm_source=rss&utm_medium=feed&utm_campaign=rss+fastcompany&utm_content=rss

Vytvořeno 5mo | 10. 10. 2024 18:10:04


Chcete-li přidat komentář, přihlaste se

Ostatní příspěvky v této skupině

TikTok’s ‘airport theory’ dares you to arrive just 15 minutes before your flight

When it comes to airports, travelers tend to fall into two camps. There are the anxious types who show up four hours early, with plenty of time to leisurely peruse duty-free and enjoy the airport

4. 3. 2025 16:10:09 | Fast company - tech
Uber will now pair Austin riders with Waymo self-driving cars

Starting today, if you call an Uber in Austin you can match with a self-driving Waymo vehicle. 

The launch in the Texas capital is part of an expanded partnership between the two te

4. 3. 2025 16:10:08 | Fast company - tech
Used Tesla prices depreciated more than any other automaker in 2024

The price of used Tesla’s Model 3 and Model Y vehicles depreciated more than any other cars in 2024, according to a Fast Company analysis of CarGurus data.

The average pri

4. 3. 2025 16:10:07 | Fast company - tech
Mozilla’s new message: We’re the only browser not backed by billionaires

As frustration with corporate power grows under the oligarch-friendly Trump administration, Mozilla Firefox

4. 3. 2025 16:10:05 | Fast company - tech
The third coming of Microsoft AI CEO Mustafa Suleyman

Microsoft employees stream down a hallway by the dozen, smartphones and paper coffee cups in hand, many clad in heavy coats on this frigid February morning. The setting is idyllic—Lake Washington

4. 3. 2025 11:30:03 | Fast company - tech
Popular female streamers are bringing on security after stars were attacked during an IRL stream

Female streamers are being told to hire security after a spate of recent attacks. 

Popular Twitch stars Valkyrae, Cinna, and Emiru were out in public at the Santa Monica Pier on Mar

4. 3. 2025 6:50:02 | Fast company - tech