Attorney General Todd Rokita announces $52 million multistate settlement with Marriott over data breach which targeted guests’ reservation info Attorney General Todd Rokita announced today that a coalition of 50 attorneys general has reached a settlement with Marriott International Inc., the result of a multi-year investigation into a massive data breach which targeted one of its guest reservation databases. Under the settlement with the attorneys general, Marriott has agreed to strengthen its data security practices using a dynamic risk-based approach, to provide certain consumer protections, and to make a $52 million payment to states. Indiana will receive over $900,000 from the settlement. “Protecting Hoosiers’ personal data, whether they are checking into a hotel or just checking out potential travel plans, is an important priority of our office,” Attorney General Rokita said. “That’s why we hold corporations accountable for responsibly handling consumers’ information. This settlement shows once again our resolve to make sure corporations are vigilant in following security protocols.” The Federal Trade Commission, which has coordinated closely with the states throughout this investigation, has reached a parallel settlement with Marriott. Marriott acquired Starwood in 2016 and took control of the Starwood computer network in 2016. However, from July 2014 until September 2018, intruders in the system went undetected. This led to the breach of 131.5 million guest records pertaining to customers in the United States. The impacted records included contact information, gender, dates of birth, legacy Starwood Preferred Guest information, reservation information, and hotel stay preferences, as well as a limited number of unencrypted passport numbers and unexpired payment card information. Shortly after the breach of the Starwood database was announced, a coalition of 50 attorneys general launched a multi-state investigation into the breach. Today’s settlement resolves allegations by the attorneys general that Marriott violated state consumer protection laws, personal information protection laws, and, where applicable, breach notification laws by failing to implement reasonable data security and remediate data security deficiencies, particularly when attempting to use and integrate Starwood into its systems. Under the terms of the settlement, Marriott has agreed to strengthen and continually improve its cybersecurity practices. Some of the specific measures include:
As part of the settlement, Marriott will give consumers specific protections, including a data deletion option, even if consumers do not currently have that right under state law. Marriott must offer multi-factor authentication to consumers for their loyalty rewards accounts, such as Marriott Bonvoy, as well as reviews of those accounts if there is suspicious activity.
A headshot of Attorney General Rokita is available online. # # #
|