Marriott settles with the FTC for $52 million over data breaches

Marriott International has agreed to pay $52 million and make changes to bolster its data security to resolve state and federal claims related to major data breaches that affected more than 300 million of its customers worldwide.

The Federal Trade Commission and a group of attorneys general from 49 states and the District of Columbia announced the terms of separate settlements with Marriott on Wednesday. The FTC and the states ran parallel investigations into three data breaches, which took place between 2014 and 2020.

As a result of the data breaches, “malicious actors” obtained the passport information, payment card numbers, loyalty numbers, dates of birth, email addresses and/or personal information from hundreds of millions of consumers, according to the FTC’s proposed complaint.

The FTC claimed that Marriott and subsidiary Starwood Hotels & Resorts Worldwide’s poor data security practices led to the breaches.

Specifically, the agency alleged that the hotel operator failed to secure its computer system with appropriate password controls, network monitoring or other practices to safeguard data.

As part of its proposed settlement with the FTC, Marriott agreed to “implement a robust information security program” and provide all of its U.S. customers with a way to request that any personal information associated with their email address or loyalty rewards account number be deleted.

Marriott also settled similar claims brought by the group of attorneys general. In addition to agreeing to strengthen its data security practices, the hotel operator also will pay $52 million penalty to be split by the states.

In a statement on its website Wednesday, Bethesda, Maryland-based Marriott noted that it made no admission of liability as part of its agreements with the FTC and states. It also said it has already put in place data privacy and information security enhancements.

In early 2020, Marriott noticed that an unexpected amount of guest information was accessed using login credentials of two employees at a franchised property. At the time, the company estimated that the personal data of about 5.2. million guests worldwide might have been affected.

In November 2018, Marriott announced a massive data breach in which hackers accessed information on as many as 383 million guests. In that case, Marriott said unencrypted passport numbers for at least 5.25 million guests were accessed, as well as credit card information for 8.6 million guests. The affected hotel brands were operated by Starwood before it was acquired by Marriott in 2016.

The FBI led the investigation of that data theft, and investigators suspected the hackers were working on behalf of the Chinese Ministry of State Security, the rough equivalent of the CIA.

—Alex Veiga, AP Business Writer

https://www.fastcompany.com/91207103/52-million-settlement-announced-between-marriott-ftc?partner=rss&utm_source=rss&utm_medium=feed&utm_campaign=rss+fastcompany&utm_content=rss

Created 3mo | Oct 10, 2024, 6:10:04 PM


Login to add comment

Other posts in this group

Find out who’s behind any phone number with this free lookup tool

I don’t know about you, but practically every time my phone rings, my heart rate starts skyrocketing.

Who the hell could be calling me? What in the world do they want? And why, for the l

Jan 5, 2025, 7:50:03 AM | Fast company - tech
‘This app saved our business’: Small businesses are bracing for a TikTok ban

As the clock ticks closer to a U.S. ban on TikTok, small businesses are bracing for the loss of an app that has, in many cases, proven vital for their success.

Millions of small business

Jan 5, 2025, 5:30:04 AM | Fast company - tech
How Big Tech became the world’s most powerful ‘religion’ and why we need to become agnostic

Greg Epstein is the Humanist chaplain at Harvard University and at MIT, where he advises students, faculty, and staff members on ethical and existential concerns from a humanist perspective. He ha

Jan 4, 2025, 10:50:02 AM | Fast company - tech
3 hidden reasons you keep running out of iCloud storage

Apple gives every iCloud user 5GB of free storage space. This storage space can be used for any

Jan 4, 2025, 10:50:02 AM | Fast company - tech
Apple’s Siri settlement feeds the ‘eavesdropping iPhone’ narrative

Apple, which has built its brand on data privacy, settled a class action suit this week in w

Jan 3, 2025, 11:20:03 PM | Fast company - tech
Dating Wrapped: TikTok users are crunching the numbers on their dating life

If Spotify Wrapped left you underwhelmed this year, TikTok’s “Dating Wrapped” trend is here to sp

Jan 3, 2025, 8:50:03 PM | Fast company - tech
Dating Sunday 2025: The busiest day on dating apps is almost here

Dating apps are gearing up for their busiest day of the year: Dating Sunday. 

This landmark day in the dating world always lands on the first Sunday of January. The idea is that sin

Jan 3, 2025, 4:20:06 PM | Fast company - tech