On October 16, 2024
State News

Nationwide multi-state settlement with Marriott amounts to $52 million

Vermont Attorney General Charity Clark announced on Oct. 9 that a coalition of 50 attorneys general has reached a settlement with Marriott International, Inc. after an investigation into a large multi-year data breach of one of Marriott’s Starwood guest reservation databases. Under the settlement, Marriott has agreed to strengthen its data security practices using a dynamic risk-based approach, pay $52 million to states, and provide additional consumer protections. Vermont will receive $590,292.25 from the settlement. 

The Federal Trade Commission, which has been coordinating closely with the states throughout their investigation, has reached a parallel settlement with Marriott.

“This case is a $52 million reminder that good data hygiene, such as data minimization, can protect not only consumers but also businesses that suffer a data breach,” said Clark. 

Marriott acquired Starwood in 2016 and took control of the Starwood computer network in 2016.  From July 2014 until September 2018, intruders into this computer network went undetected. This failure led to the breach of 131.5 million guest records pertaining to customers in the U.S. The impacted records included contact information, gender, dates of birth, legacy Starwood Preferred Guest information, reservation information, hotel stay preferences, and a limited number of unencrypted passport numbers and unexpired payment card information.

Shortly after the breach of the Starwood database was announced, a coalition of 50 attorneys general launched a multi-state investigation into the breach. The Oct. 9 settlement resolves allegations by Attorney General Clark that Marriott violated Vermont’s Consumer Protection Act and Security Breach Notification Act by failing to implement reasonable data security and remediate data security deficiencies, particularly when attempting to use and integrate Starwood into its systems.

Under the terms of the settlement, Marriott has agreed to strengthen and continually improve its cybersecurity practices. As part of the settlement, Marriott will give consumers specific protections, including a data deletion option, even if consumers do not currently have that right under state law. 

Marriott must offer multi-factor authentication to consumers for their loyalty rewards accounts — such as Marriott Bonvoy— as well as reviews of those accounts if there is any suspicious activity.

Do you want to submit feedback to the editor?

Send Us An Email!

Related Posts

Two members, including chair, resign from the Commission on the Future of Public Education in Vermont

June 25, 2025
By Corey McDonald/VTDigger Two members of the Commission on the Future of Public Education in Vermont, including the commission’s chair, announced last week they would be resigning, saying they no longer believed their efforts would make any impact. Meagan Roy, the chair of the commission, and Nicole Mace, the former representative of the Vermont School Boards…

Vt plastic bag use dropped 91% following ban, researchers find

June 25, 2025
In the midst of 2020 Covid measures, another change took place in Vermont: A law went into effect banning businesses from offering plastic bags to customers, with paper bags only available for a fee. A 2023 analysis of a survey of hundreds of Vermonters found the law appeared to have worked. Plastic bag use in…

A Roadmap

June 25, 2025
The Vermont Legislature adjourned Monday evening, June 16, following the passage of H.454, the education reform plan. I call it a roadmap as the legislation lays out a list of changes that will take place over the next few years. And as various studies and reports come back in, there will also likely be adjustments,…

Vermont to get over $21 million in nationwide settlement with Purdue Pharma and the Sacklers

June 25, 2025
Attorney General Charity Clark announced June 16 that all 55 attorneys general, representing all eligible states and U.S. territories, have agreed to sign on to a $7.4 billion settlement with Purdue Pharma and its owners, the Sackler family. This settlement was reached after the previous settlement was rejected by the U.S. Supreme Court. It resolves…