On October 16, 2024
State News

Nationwide multi-state settlement with Marriott amounts to $52 million

Vermont Attorney General Charity Clark announced on Oct. 9 that a coalition of 50 attorneys general has reached a settlement with Marriott International, Inc. after an investigation into a large multi-year data breach of one of Marriott’s Starwood guest reservation databases. Under the settlement, Marriott has agreed to strengthen its data security practices using a dynamic risk-based approach, pay $52 million to states, and provide additional consumer protections. Vermont will receive $590,292.25 from the settlement. 

The Federal Trade Commission, which has been coordinating closely with the states throughout their investigation, has reached a parallel settlement with Marriott.

“This case is a $52 million reminder that good data hygiene, such as data minimization, can protect not only consumers but also businesses that suffer a data breach,” said Clark. 

Marriott acquired Starwood in 2016 and took control of the Starwood computer network in 2016.  From July 2014 until September 2018, intruders into this computer network went undetected. This failure led to the breach of 131.5 million guest records pertaining to customers in the U.S. The impacted records included contact information, gender, dates of birth, legacy Starwood Preferred Guest information, reservation information, hotel stay preferences, and a limited number of unencrypted passport numbers and unexpired payment card information.

Shortly after the breach of the Starwood database was announced, a coalition of 50 attorneys general launched a multi-state investigation into the breach. The Oct. 9 settlement resolves allegations by Attorney General Clark that Marriott violated Vermont’s Consumer Protection Act and Security Breach Notification Act by failing to implement reasonable data security and remediate data security deficiencies, particularly when attempting to use and integrate Starwood into its systems.

Under the terms of the settlement, Marriott has agreed to strengthen and continually improve its cybersecurity practices. As part of the settlement, Marriott will give consumers specific protections, including a data deletion option, even if consumers do not currently have that right under state law. 

Marriott must offer multi-factor authentication to consumers for their loyalty rewards accounts — such as Marriott Bonvoy— as well as reviews of those accounts if there is any suspicious activity.

Do you want to submit feedback to the editor?

Send Us An Email!

Related Posts

1,700 pounds of Cabot butter recalled in Vermont and 6 other states for possible fecal contamination

April 16, 2025
By Habib Sabet/VtDigger Cabot Creamery has issued a voluntary recall for nearly a ton of butter due to potential fecal contamination, the brand’s parent company, Agri-Mark Inc., announced April 9. The recall covers 189 cases of the iconic Vermont brand’s 8-oz. Extra Creamy Premium Butter across Vermont, New York, Pennsylvania, Maine, Connecticut, New Hampshire and…

Moving Day

April 16, 2025
“Moving Day” in the world of golf often refers to Saturday’s third round play at the annual Masters Golf Tournament at Augusta Country Club. This is when top players often move into contention for Sunday’s final round for the championship, just like Rory McIlroy did this past Saturday with an impressive six under par performance.…

IMLS terminates grant for Vermont Historical Society’s local history program

April 16, 2025
The Vermont Historical Society (VHS) announced that the Institute of Museum and Library Services (IMLS) terminated its federal funding for the Activating 21st Century Local History Training Program, effective April 8. The decision follows President Donald Trump’s recent executive order to defund several federal agencies, including IMLS. In a letter from acting IMLS director Keith…

Palestinian man legally living in White River Junction was detained during citizenship interview in Vermont

April 16, 2025
By Auditi Guha/VTDigger Masked men in plainclothes detained an Upper Valley resident in Colchester during a scheduled citizenship interview Monday morning, April 14, despite his status as a lawful U.S. permanent resident. Mohsen Mahdawi’s lawyers filed a petition Monday alleging unlawful detention in the U.S. District Court in Vermont. Judge William Sessions III then issued a temporary restraining order saying…