Marriott agrees to pay $52 million, beef up data security to resolve probes over data breaches

Marriott International has reached an agreement to pay $52 million and enhance its data security measures in order to settle investigations into major data breaches that impacted over 300 million customers globally. The Federal Trade Commission (FTC) and a coalition of attorneys general from 49 states and the District of Columbia disclosed the terms of their settlements with Marriott recently. These investigations were conducted in response to three data breaches that occurred between 2014 and 2020.

The FTC and the states determined that due to these breaches, malicious actors were able to access passport information, payment card numbers, loyalty numbers, dates of birth, email addresses, and other personal details from hundreds of millions of consumers. The FTC stated that Marriott and its subsidiary Starwood Hotels & Resorts Worldwide were culpable for these breaches as a result of inadequate data security practices. They alleged that the hotel operator failed to implement sufficient password controls, network monitoring, and other protective measures for securing data.

As part of the settlement with the FTC, Marriott has agreed to establish a comprehensive information security program and offer all its U.S. customers the option to request the deletion of any personal information linked to their email address or loyalty rewards account number. Additionally, Marriott has resolved similar claims with the group of attorneys general. In addition to committing to reinforcing its data security protocols, the hotel company will pay a $52 million fine, to be divided among the states involved.

In a statement on its website, Marriott, based in Bethesda, Maryland, clarified that it did not admit liability as part of the agreements with the FTC and the states. The company highlighted that it has already implemented enhancements to data privacy and information security. The breaches came to light in early 2020 when Marriott discovered unauthorized access to guest information using the login credentials of two employees at a franchise property. Approximately 5.2 million guests worldwide were estimated to be affected at that time.

Back in November 2018, Marriott disclosed a significant data breach where hackers gained access to data on as many as 383 million guests. The exposed information included unencrypted passport numbers for at least 5.25 million guests and credit card details for 8.6 million guests. The affected brands were under Starwood’s operation before being acquired by Marriott in 2016. The FBI spearheaded the investigation into this breach, suspecting the hackers were affiliated with the Chinese Ministry of State Security.

Marriott’s commitment to paying the fine and fortifying its data security practices underscores the importance of safeguarding customer information in an increasingly digital landscape. The resolution of these probes marks a step towards ensuring greater accountability and protection for consumers’ personal data.

Leave a Reply

Your email address will not be published. Required fields are marked *