Court Rules
All enforcement actions
SettlementCritical RiskMultistate

Multistate $52M Settlement with Marriott Over Multi-Year Data Breach

Marriott International, Inc.October 9, 2024New York Attorney General

Penalty Amount

$52,000,000

Consumers Affected

131,500,000

Summary

A multistate coalition of 50 attorneys general led by New York AG Letitia James reached a $52 million settlement with Marriott International, Inc. over a 2014-2018 data breach of its Starwood subsidiary’s guest reservation database that exposed 131.5 million consumers’ personal information. The breach, which went undetected for four years, compromised contact details, dates of birth, passport numbers, payment card information, and loyalty program data. Marriott is required to overhaul its data security practices, implement new compliance measures, and allow customers to delete their stored data as part of the settlement.

Remedy

Marriott must pay $52 million in total penalties ($2.29 million to New York) and implement sweeping data security reforms over 20 years. Requirements include biennial independent third-party security assessments, a comprehensive Information Security Program with CEO-level reporting and employee training, data minimization and disposal protocols, enhanced vendor and franchisee oversight with risk assessments for critical IT vendors, and post-acquisition security integration plans. Marriott must also allow customers to delete their stored data, offer multi-factor authentication for loyalty accounts, and monitor those accounts for suspicious activity.

Monetary PenaltyInjunctionAudit RequirementCompliance ProgramData DeletionReporting Requirements

Contract Impact

In-house legal teams should review all vendor agreements, especially those with cloud providers and IT vendors, to ensure they include mandatory risk assessments, clear security obligations, and compliance with the company’s data security policies. Contracts with franchisees should also be updated to require adherence to information security programs and regular security reporting. Acquisition agreements need to include provisions requiring prompt security assessments of target companies and integration plans to address deficiencies. Additionally, customer-facing agreements should be updated to include clear data deletion rights and multi-factor authentication options for loyalty accounts. Data retention clauses should be revised to minimize unnecessary data collection and require timely disposal of outdated customer information.

Contract Search Terms

Critical IT Vendorvendor risk assessmentdata minimizationthird-party security auditdata retention policyacquisition security integrationcustomer data deletioninformation security program

Violation Types

Entity Details

Entity

Marriott International, Inc.

Also known as: Marriott

Industry

Other

Multistate Coalition

Official Sources

Source Evidence

Entity Name
"Marriott International, Inc. (Marriott)"
Fine Amount
"pay $52 million in penalties"
Violation Types
"intruders in its system for four years without getting detected, leading to a data breach that affected 131.5 million customers nationwide"
Violation Types
"intruders accessed and stayed on Starwood’s databases undetected for years. This intrusion led to the breach of 131.5 million customers’ personal information."
Consumers Affected
"131.5 million customers nationwide"
Event Date
"October 9, 2024"

Related Enforcement Actions

NJ

Marriott International, Inc.

$52.0M

A multistate coalition of 50 attorneys general, including New Jersey, reached a $52 million settlement with Marriott International, Inc. for two data breaches that exposed personal information of over 131 million consumers. The breaches resulted from inadequate cybersecurity practices at Starwood and Marriott networks. The settlement mandates comprehensive security improvements and monetary penalties.

CT

Marriott International, Inc.

$52.0M

A multistate settlement with Marriott International for a data breach affecting 131.5 million guest records. Marriott failed to secure the Starwood network from 2014 to 2018, exposing personal information. The settlement includes a $52 million payment and requires Marriott to implement enhanced cybersecurity measures and consumer protections.

TX

Marriott International, Inc.

$3.5M

Texas Attorney General Ken Paxton secured a $3.5 million settlement with Marriott International, Inc. following an investigation into a data breach of the company’s reservation database that exposed 131 million U.S. guest records. The breach included sensitive customer information such as contact details, dates of birth, unencrypted passport numbers, and unexpired payment card information. Marriott is required to implement enhanced data security measures, including zero-trust principles and regular security reporting to its CEO, as part of the settlement.

NY

Paramount Skydance Corp.

New York Attorney General Letitia James obtained a temporary restraining order from the U.S. District Court for the Northern District of California blocking Paramount Skydance Corp.'s proposed $110 billion merger with Warner Bros. Discovery, Inc. The lawsuit alleges the merger would illegally reduce competition in film and television, leading to higher prices and fewer choices for consumers.

NY

23andMe

$18.0M

New York Attorney General Letitia James and a bipartisan coalition of 42 other attorneys general secured an $18 million settlement from genetic testing company 23andMe for failing to protect customers' private genetic data. The October 2023 data breach exposed sensitive genetic information of 6.9 million consumers, including 305,245 in New York, with some data published for sale on the dark web. The settlement includes monetary penalties and new data protection requirements for the company and its successor, 23andMe Research Institute.

NY

Paramount Skydance Corp.

New York Attorney General Letitia James and 11 other attorneys general filed a lawsuit to block the proposed $110 billion merger between Paramount Skydance Corp. and Warner Bros. Discovery, Inc., alleging the merger would violate antitrust law by reducing competition in theatrical film releases and basic cable television markets, leading to higher prices for consumers and fewer diverse entertainment options.