Marriott agrees to pay $52 million, beef up data security to resolve probes over data breaches

Date:

Share post:


Marriott International has agreed to pay $52 million and make changes to bolster its data security to resolve state and federal claims related to major data breaches that affected more than 300 million of its customers worldwide.

The Federal Trade Commission and a group of attorneys general from 49 states and the District of Columbia announced the terms of separate settlements with Marriott on Wednesday. The FTC and the states ran parallel investigations into three data breaches, which took place between 2014 and 2020.

As a result of the data breaches, “malicious actors” obtained the passport information, payment card numbers, loyalty numbers, dates of birth, email addresses and/or personal information from hundreds of millions of consumers, according to the FTC’s proposed complaint.

The FTC claimed that Marriott and subsidiary Starwood Hotels & Resorts Worldwide’s poor data security practices led to the breaches.

Specifically, the agency alleged that the hotel operator failed to secure its computer system with appropriate password controls, network monitoring or other practices to safeguard data.

As part of its proposed settlement with the FTC, Marriott agreed to “implement a robust information security program” and provide all of its U.S. customers with a way to request that any personal information associated with their email address or loyalty rewards account number be deleted.

Marriott also settled similar claims brought by the group of attorneys general. In addition to agreeing to strengthen its data security practices, the hotel operator also will pay $52 million penalty to be split by the states.

In a statement on its website Wednesday, Bethesda, Maryland-based Marriott noted that it made no admission of liability as part of its agreements with the FTC and states. It also said it has already put in place data privacy and information security enhancements.

In early 2020, Marriott noticed that an unexpected amount of guest information was accessed using login credentials of two employees at a franchised property. At the time, the company estimated that the personal data of about 5.2. million guests worldwide might have been affected.

In November 2018, Marriott announced a massive data breach in which hackers accessed information on as many as 383 million guests. In that case, Marriott said unencrypted passport numbers for at least 5.25 million guests were accessed, as well as credit card information for 8.6 million guests. The affected hotel brands were operated by Starwood before it was acquired by Marriott in 2016.

The FBI led the investigation of that data theft, and investigators suspected the hackers were working on behalf of the Chinese Ministry of State Security, the rough equivalent of the CIA.



Source link

Lisa Holden
Lisa Holden
Lisa Holden is a news writer for LinkDaddy News. She writes health, sport, tech, and more. Some of her favorite topics include the latest trends in fitness and wellness, the best ways to use technology to improve your life, and the latest developments in medical research.

Recent posts

Related articles

Lithuania votes in a weekend general election with many looking for change despite good economy

VILNIUS, Lithuania -- Despite economic successes, Lithuania’s center-right coalition could be replaced by the opposition Social Democrats...

Social Security cost-of-living benefits increase announcement coming Thursday

WASHINGTON -- More than 70 million Social Security recipients will learn Thursday how big a cost-of-living increase...

Stock market today: Asian shares rise after Wall Street rally, and China promises a briefing

TOKYO -- Asian shares mostly rose Thursday, as market optimism got a perk from the record highs...

Close call at Nashville airport came after planes were directed to same runway, probe shows

WASHINGTON -- Investigators said Wednesday that air traffic controllers cleared an Alaska Airlines jet to take off...

2 teams suing NASCAR ask court to recognize them as chartered while antitrust case proceeds

CHARLOTTE, N.C. -- The two teams suing NASCAR asked a judge for a preliminary injunction Wednesday so...

Climate solution: Form Energy secures $405M to speed development of long-awaited 100-hour battery

Form Energy, a company that is beginning to produce a longer-lasting alternative to lithium batteries, hit a...

Polluted waste from Florida's fertilizer industry is in the path of Milton's fury

As Hurricane Milton bears down on Florida’s west coast with powerful winds and flooding rain, environmentalists are...

Ratan Tata, the former chairman of Indian conglomerate Tata Sons, dies at age 86

NEW DELHI -- Ratan Tata, a former chairman of Indian conglomerate Tata Sons, died at a Mumbai...