On October 16, 2024
State News

Nationwide multi-state settlement with Marriott amounts to $52 million

Vermont Attorney General Charity Clark announced on Oct. 9 that a coalition of 50 attorneys general has reached a settlement with Marriott International, Inc. after an investigation into a large multi-year data breach of one of Marriott’s Starwood guest reservation databases. Under the settlement, Marriott has agreed to strengthen its data security practices using a dynamic risk-based approach, pay $52 million to states, and provide additional consumer protections. Vermont will receive $590,292.25 from the settlement. 

The Federal Trade Commission, which has been coordinating closely with the states throughout their investigation, has reached a parallel settlement with Marriott.

“This case is a $52 million reminder that good data hygiene, such as data minimization, can protect not only consumers but also businesses that suffer a data breach,” said Clark. 

Marriott acquired Starwood in 2016 and took control of the Starwood computer network in 2016.  From July 2014 until September 2018, intruders into this computer network went undetected. This failure led to the breach of 131.5 million guest records pertaining to customers in the U.S. The impacted records included contact information, gender, dates of birth, legacy Starwood Preferred Guest information, reservation information, hotel stay preferences, and a limited number of unencrypted passport numbers and unexpired payment card information.

Shortly after the breach of the Starwood database was announced, a coalition of 50 attorneys general launched a multi-state investigation into the breach. The Oct. 9 settlement resolves allegations by Attorney General Clark that Marriott violated Vermont’s Consumer Protection Act and Security Breach Notification Act by failing to implement reasonable data security and remediate data security deficiencies, particularly when attempting to use and integrate Starwood into its systems.

Under the terms of the settlement, Marriott has agreed to strengthen and continually improve its cybersecurity practices. As part of the settlement, Marriott will give consumers specific protections, including a data deletion option, even if consumers do not currently have that right under state law. 

Marriott must offer multi-factor authentication to consumers for their loyalty rewards accounts — such as Marriott Bonvoy— as well as reviews of those accounts if there is any suspicious activity.

Do you want to submit feedback to the editor?

Send Us An Email!

Related Posts

Vt Legislature advances bill to ban toxic ‘forever chemicals’ from firefighting gear, dental floss, cleaning products

June 4, 2025
The Vermont Senate and House advance legislation (H.238) May 29 that would outlaw the use of toxic perfluoroalkyl and polyfluoroalkyl substances (PFAS) in firefighting gear, dental floss, cleaning products, and fluorine-treated containers—a critical step in reducing Vermonters’ exposure to these harmful substances. The Senate expanded the bill as passed by the House by adding a provision that…

To be continued…

June 4, 2025
A final compromise on education reform proved elusive late Friday, and at about 11 p.m., the Senate adjourned, followed by the House at about 11:30 p.m. As late as 10 p.m., legislative leaders were still hopeful that the six conferees (three House and three Senate members) could reach a deal sometime before midnight that would…

Nearing the end?

June 4, 2025
After passing several challenging bills in the last few weeks, the Vermont Legislature adjourned until June 16 due to an impasse over negotiations on our education transformation bill, H.454. Many other bills addressing housing, homelessness, healthcare, and several other major issues required compromises from both the House and the Senate in order to be passed…

Vermont gets $23 million from ongoing settlement with tobacco manufacturers

June 4, 2025
Attorney General Charity Clark announced last month that Vermont received a total of $23,132,483.92 from tobacco manufacturers under the tobacco Master Settlement Agreement (MSA). Annually, Vermont receives monies from tobacco manufacturers from the MSA, which resolved the state’s lawsuit filed in the 1990s. The settlement funds are credited to the state’s Tobacco Fund, and the…