10/09/2024 | News release | Distributed by Public on 10/09/2024 15:55
DEPARTMENT OF COMMERCE AND CONSUMER AFFAIRS
KA ʻOIHANA PILI KĀLEPA
OFFICE OF CONSUMER PROTECTION
JOSH GREEN, M.D.
GOVERNOR | KE KIAʻĀINA
NADINE Y. ANDO
DIRECTOR | KA LUNA HOʻOKELE
THOMAS MANA MORIARTY
EXECUTIVE DIRECTOR
FOR IMMEDIATE RELEASE
October 9, 2024
$52 Million Multistate Settlement with Marriott for Data Breach of Starwood Guest Reservation Database
HONOLULU - The state of Hawai'i Department of Commerce and Consumer Affairs Office of Consumer Protection announced today that a coalition of 50 attorneys general has reached a settlement with Marriott International, Inc. as the result of an investigation into a large multiyear data breach of one of its guest reservation databases. The Federal Trade Commission, which has been coordinating closely with the states throughout this investigation, has reached a parallel settlement with Marriott. Under the settlement with the attorneys general, Marriott has agreed to strengthening its data security practices using a dynamic risk-based approach, provide certain consumer protections, and make a $52 million payment to states. The state of Hawai'i will receive $438,045.00 from the settlement.
Marriott acquired Starwood in 2016 and took control of the Starwood computer network within the same year. However, from July 2014 until September 2018, intruders in the system went undetected. This led to the breach of 131.5 million guest records pertaining to customers in the United States. The impacted records included contact information, gender, dates of birth, legacy Starwood Preferred Guest information, reservation information, and hotel stay preferences, as well as a limited number of unencrypted passport numbers and unexpired payment card information.
Shortly after the breach of the Starwood database was announced, a coalition of 50 attorneys general launched a multistate investigation into the breach. Today's settlement resolves allegations by the attorneys general that Marriott violated state consumer protection laws, personal information protection laws, and, where applicable, breach-notification laws by failing to implement reasonable data security measures and remediate data security deficiencies, particularly when attempting to use and integrate Starwood into its systems.
"When companies choose to collect and store consumer data, they must take steps to secure it," stated Executive Director of the Office of Consumer Protection, Mana Moriarty. "We will continue to hold businesses accountable for their failure to do so."
Under the terms of the settlement, Marriott has agreed to strengthen and continually improve its cybersecurity practices. Some of the specific measures include:
These settlement terms are grounded in a well-developed risk-based approach in which Marriott not only needs to conduct an annual enterprise level risk assessment, but it must also perform risk analyses throughout the year for changes to security controls. Those ongoing risk assessments must address the criteria of "harm to others" - which would include potential harm to consumers.
As part of the settlement, Marriott will give consumers specific protections, including a data deletion option, even if consumers do not currently have that right under state law. Marriott must offer multifactor authentication to consumers for their loyalty rewards accounts, such as Marriott Bonvoy, as well as reviews of those accounts if there is suspicious activity.
Connecticut, Maryland, and Oregon as well as the District of Columbia, Illinois, Louisiana, Massachusetts, North Carolina, and Texas co-led the multistate investigation, assisted by the Executive Committee of Alabama, Arizona, Arkansas, Florida, Nebraska, New Jersey, New York, Ohio, Pennsylvania, and Vermont, and were joined by Alaska, Colorado, Delaware, Georgia, Hawai'i, Idaho, Indiana, Iowa, Kansas, Kentucky, Maine, Michigan, Minnesota, Mississippi, Missouri, Montana, Nevada, New Hampshire, New Mexico, North Dakota, Oklahoma, Rhode Island, South Carolina, South Dakota, Tennessee, Utah, Virginia, Washington, West Virginia, Wisconsin, and Wyoming.
###
Media Contact:
William Nhieu
Communications Officer
Department of Commerce and Consumer Affairs
Email: [email protected]
Phone: 808-586-7582