On October 16, 2024
State News

Nationwide multi-state settlement with Marriott amounts to $52 million

Vermont Attorney General Charity Clark announced on Oct. 9 that a coalition of 50 attorneys general has reached a settlement with Marriott International, Inc. after an investigation into a large multi-year data breach of one of Marriott’s Starwood guest reservation databases. Under the settlement, Marriott has agreed to strengthen its data security practices using a dynamic risk-based approach, pay $52 million to states, and provide additional consumer protections. Vermont will receive $590,292.25 from the settlement. 

The Federal Trade Commission, which has been coordinating closely with the states throughout their investigation, has reached a parallel settlement with Marriott.

“This case is a $52 million reminder that good data hygiene, such as data minimization, can protect not only consumers but also businesses that suffer a data breach,” said Clark. 

Marriott acquired Starwood in 2016 and took control of the Starwood computer network in 2016.  From July 2014 until September 2018, intruders into this computer network went undetected. This failure led to the breach of 131.5 million guest records pertaining to customers in the U.S. The impacted records included contact information, gender, dates of birth, legacy Starwood Preferred Guest information, reservation information, hotel stay preferences, and a limited number of unencrypted passport numbers and unexpired payment card information.

Shortly after the breach of the Starwood database was announced, a coalition of 50 attorneys general launched a multi-state investigation into the breach. The Oct. 9 settlement resolves allegations by Attorney General Clark that Marriott violated Vermont’s Consumer Protection Act and Security Breach Notification Act by failing to implement reasonable data security and remediate data security deficiencies, particularly when attempting to use and integrate Starwood into its systems.

Under the terms of the settlement, Marriott has agreed to strengthen and continually improve its cybersecurity practices. As part of the settlement, Marriott will give consumers specific protections, including a data deletion option, even if consumers do not currently have that right under state law. 

Marriott must offer multi-factor authentication to consumers for their loyalty rewards accounts — such as Marriott Bonvoy— as well as reviews of those accounts if there is any suspicious activity.

Do you want to submit feedback to the editor?

Send Us An Email!

Related Posts

Good news, progress,and more work to come

May 7, 2025
The best news of the week was that Mohsen Madawi was released from detention here in Vermont.  The federal government offered no acceptable justification for Madawi’s detention, and, as a result, Judge Crawford of Vermont’s U.S. District Court freed him. The conditions of his release seem relatively simple: he is now free to go back…

Threading the needle

May 7, 2025
Last Thursday, May 1, the full Senate approved its version of the state budget for the fiscal year beginning July 1 with numerous changes from the House. On Friday the House and Senate appointed a conference committee (three House and three Senate members) to work out the differences between the two chambers. Once that happens,…

Sanders introduces Medicare for All

May 7, 2025
U.S. Senator Bernie Sanders, ranking member of the Senate Committee on Health, Education, Labor, and Pensions (HELP), alongside Rep. Pramila Jayapal (D-Wash.) and Rep. Debbie Dingell (D-Mich.), introduced the Medicare for All Act last Tuesday, April 29. Hundreds of nurses, health care providers and workers from around the nation joined the lawmakers for a press conference in…

Why did the herp cross the road? ‘Big Nights’ mean big risks for amphibians and reptiles

May 7, 2025
By Theresa Golub Editor’s note: This story is via Community News Service in partnership with Vermont State University Castleton. Across Vermont, the songs of spring peepers marking the change in seasons. Temperatures rise, snow melts and water runs into the dips and divots of the land to form vernal pools.  Biologists call those springtime basins the…