{"id":2997,"date":"2024-10-11T22:06:49","date_gmt":"2024-10-11T22:06:49","guid":{"rendered":"https:\/\/usatrustedlawyers.com\/blog\/marriotts-52m-data-breach-settlement-points-to-emerging-trend\/"},"modified":"2024-10-11T22:06:49","modified_gmt":"2024-10-11T22:06:49","slug":"marriotts-52m-data-breach-settlement-points-to-emerging-trend","status":"publish","type":"post","link":"https:\/\/usatrustedlawyers.com\/blog\/marriotts-52m-data-breach-settlement-points-to-emerging-trend\/","title":{"rendered":"Marriott&#8217;s $52M Data Breach Settlement Points to Emerging Trend"},"content":{"rendered":"\n<div data-v-84c6be9c=\"\">\n<div data-v-84c6be9c=\"\">\n<p>Marriott International and its subsidiary, Starwood Hotels &amp; Resorts Worldwide, have reached agreements with the Federal Trade Commission and 49 state attorneys general regarding a massive data breach involving its hotels.<\/p>\n<\/div>\n<p>  <!----> <!----> <!----><\/p>\n<div data-v-84c6be9c=\"\">\n<p>And some observers think the deal could be a sign of an emerging trend.<\/p>\n<\/div>\n<p> <!----> <!----> <!----> <!----><\/p>\n<div data-v-84c6be9c=\"\">\n<p>Under the\u00a0agreement, the hotel operator will pay $52 million without admitting liability for the underlying allegations.<\/p>\n<\/div>\n<p> <!----> <!----> <!----> <!----><\/p>\n<div data-v-84c6be9c=\"\">\n<p>The complaints said multiple data breaches occurred between 2014 and 2020, impacting more than 344 million customers globally.<\/p>\n<\/div>\n<p> <!---->  <!----> <!----><\/p>\n<div data-v-84c6be9c=\"\">\n<p>As part of the settlement with the FTC, Marriott and Starwood must implement a comprehensive information security program designed to enhance data protection across their hotel networks worldwide.<\/p>\n<\/div>\n<p> <!----> <!----> <!----> <!----><\/p>\n<div data-v-84c6be9c=\"\">\n<p>_____________________________________________________________________________________________________<\/p>\n<\/p><\/div>\n<p> <!----> <!----> <!----> <!----><\/p>\n<div data-v-84c6be9c=\"\">\n<p><figure>  <\/figure>\n<figure\/>\n<figure> <a href=\"https:\/\/www.law.com\/radar\/card\/wn-dc-dc-625355-district-of-columbia-v-marriott-international-inc\/\" target=\"_blank\" rel=\"noopener nofollow\">This action<\/a> was surfaced by <a href=\"https:\/\/www.law.com\/radar\/newsfeed\/\" target=\"_blank\" rel=\"noopener nofollow\">Law.com Radar, <\/a>which delivers artificial intelligence-enhanced case summaries and daily case reports from more than 2,200 state and federal courts. Click here to get started and be among the first to act on opportunities in your region, practice area, or client sector. <\/figure>\n<p>_____________________________________________________________________________________________________ <\/p>\n<\/div>\n<p> <!----> <!---->  <!----><\/p>\n<div data-v-84c6be9c=\"\">\n<h2>&#8216;States Are Becoming Much More Aggressive&#8217;<\/h2>\n<p>Kelley Kronenberg partner Timothy Shields points\u00a0out that this development highlights government efforts to combat data breaches.<\/p>\n<\/p><\/div>\n<p> <!----> <!----> <!----> <!----><\/p>\n<div data-v-84c6be9c=\"\">\n<p><figure id=\"attachment_214526\" align=\"alignright\" width=\"200\"> <img loading=\"lazy\" decoding=\"async\" class=\"size-medium wp-image-214526\" src=\"https:\/\/images.law.com\/cdn-cgi\/image\/format=auto,fit=contain\/http:\/\/images.law.com\/contrib\/content\/uploads\/sites\/392\/2024\/10\/Timothy-Shields-Vert-202410111234-200x300.jpg\" alt=\"\" width=\"200\" height=\"300\" title=\"\"> Kelley Kronenberg partner Timothy Shields. Courtesy photo <\/figure>\n<\/p>\n<\/div>\n<p> <!----> <!----> <!----> <!----><\/p>\n<div data-v-84c6be9c=\"\">\n<p>&#8220;Individual states are becoming much more aggressive in addressing data privacy concerns absent a federal consumer data privacy law,&#8221; Shields said.<\/p>\n<\/div>\n<p> <!----> <!----> <!----> <!----><\/p>\n<div data-v-84c6be9c=\"\">\n<p>While not involved in the FTC action,\u00a0the Broward attorney&#8217;s practice focuses\u00a0on technology and intellectual property, including copyright, trademark, the digital economy, data privacy and data breach response.<\/p>\n<\/div>\n<p> <!----> <!----> <!----> <!----><\/p>\n<div data-v-84c6be9c=\"\">\n<p>&#8220;I see this trend continuing over the next several years,&#8221; Shields said. &#8220;The agreement with the FTC outlines several cybersecurity steps for Marriott, which really are just standard best practices any organization should already be doing themselves or in partnership with a cybersecurity professional.&#8221;<\/p>\n<\/div>\n<p> <!----> <!----> <!----> <!----><\/p>\n<div data-v-84c6be9c=\"\">\n<p>When contacted, Marriott said as part of the resolutions with the FTC and the state attorneys general,\u00a0it will continue implementing enhancements to its data privacy and information security programs, many of which are already in place or in progress.<\/p>\n<\/div>\n<p> <!----> <!----> <!----> <!----><\/p>\n<div data-v-84c6be9c=\"\">\n<p>&#8220;For example, Marriott is offering U.S. customers a process to request deletion of their personal information, offering an online portal for Marriott\u00a0Bonvoy\u00ae\u00a0members to report potentially suspicious loyalty account activity,\u00a0and\u00a0implementing a multi-factor authentication option for Marriott\u00a0Bonvoy\u00ae\u00a0accounts,&#8221; the <a href=\"https:\/\/news.marriott.com\/news\/2024\/10\/09\/marriott-international-resolves-state-attorneys-general-and-federal-trade-commission-investigations\" target=\"_blank\" rel=\"noopener nofollow\">company statement<\/a> read.<\/p>\n<\/div>\n<p> <!----> <!----> <!----> <!----><\/p>\n<div data-v-84c6be9c=\"\">\n<p>Marriott and Starwood also agreed to provide all its U.S. customers with a way\u00a0to delete personal information\u00a0associated with their email address or loyalty rewards account number.<\/p>\n<\/div>\n<p> <!----> <!----> <!----> <!----><\/p>\n<div data-v-84c6be9c=\"\">\n<p>In addition, the proposed settlement requires Marriott to review loyalty rewards accounts on\u00a0customer\u00a0request and restore stolen loyalty points.<\/p>\n<\/p><\/div>\n<p> <!----> <!----> <!----> <!----><\/p>\n<div data-v-84c6be9c=\"\">\n<p><figure id=\"attachment_214527\" align=\"alignleft\" width=\"200\"> <img loading=\"lazy\" decoding=\"async\" class=\"size-medium wp-image-214527\" src=\"https:\/\/images.law.com\/cdn-cgi\/image\/format=auto,fit=contain\/http:\/\/images.law.com\/contrib\/content\/uploads\/sites\/392\/2024\/10\/FTC-sign-Vert-202410111057-200x300.jpg\" alt=\"\" width=\"200\" height=\"300\" title=\"\"> Federal Trade Commission building. Photo by Diego M. Radzinschi\/ALM <\/figure>\n<\/p>\n<\/div>\n<p> <!----> <!----> <!----> <!----> <!----> <!----> <!----> <!----><\/p>\n<div data-v-84c6be9c=\"\">\n<p>&#8220;Marriott&#8217;s poor security practices led to multiple breaches affecting hundreds of millions of customers,&#8221; said Samuel Levine, director of the FTC&#8217;s Bureau of Consumer Protection. &#8220;The FTC&#8217;s action today, in coordination with our state partners, will ensure that Marriott improves its data security practices in hotels around the globe.&#8221;<\/p>\n<\/div>\n<p> <!----> <!----> <!----> <!----><\/p>\n<div data-v-84c6be9c=\"\">\n<p>The FTC and the states worked in parallel on the investigation.<\/p>\n<\/div>\n<p> <!----> <!----> <!----> <!----><\/p>\n<div data-v-84c6be9c=\"\">\n<p>According to the FTC, it does not have legal authority to obtain civil penalties in this case.<\/p>\n<p><iframe loading=\"lazy\" src=\"https:\/\/drive.google.com\/file\/d\/1WDkOfXpyKjqkpsV29pbMplFtxWGFfTDc\/preview\" width=\"640\" height=\"480\" allow=\"autoplay\"><\/iframe><\/p>\n<\/div>\n<p> <!----> <!----> <!----> <!----><\/p>\n<div data-v-84c6be9c=\"\">\n<p>&#8220;Protecting guests&#8217; personal data remains a top priority for Marriott. These resolutions reaffirm the company&#8217;s continued focus on and significant investments in\u00a0maintaining and adapting its programs and systems to assess, identify, and manage risks from evolving cybersecurity threats,&#8221; Marriott said.<\/p>\n<\/div>\n<p> <!----> <!----> <!----> <!----><\/p>\n<div data-v-84c6be9c=\"\">\n<p>Shields, the data privacy lawyer, suggests there is a valuable lesson to be learned from this government action.<\/p>\n<\/div>\n<p> <!----> <!----> <!----> <!----><\/p>\n<div data-v-84c6be9c=\"\">\n<p>&#8220;Individuals need to be much more cautious in how they share their information,&#8221; Shield said. &#8220;It will get leaked. Treat your data like you would treat your money. Your personal data is just like currency\u2014take the same precautions.&#8221;<\/p>\n<\/div>\n<p> <!----> <!----> <!----> <!----><\/p>\n<div data-v-84c6be9c=\"\">\n<p>The FTC&#8217;s proposed consent agreement will be open for public comment before it becomes final. After\u00a0that, Marriott must comply with the order for 20 years, with third-party assessments every two years.<\/p>\n<\/p><\/div>\n<p> <!----> <!----> <!----> <!----><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Marriott International and its subsidiary, Starwood Hotels &amp; Resorts Worldwide, have reached agreements with the Federal Trade Commission and 49 state attorneys general regarding a massive data breach [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2998,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[3809,293,292,1925,3808,2047,399,1479],"class_list":["post-2997","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-lawyers","tag-52m","tag-breach","tag-data","tag-emerging","tag-marriotts","tag-points","tag-settlement","tag-trend"],"_links":{"self":[{"href":"https:\/\/usatrustedlawyers.com\/blog\/wp-json\/wp\/v2\/posts\/2997","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/usatrustedlawyers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/usatrustedlawyers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/usatrustedlawyers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/usatrustedlawyers.com\/blog\/wp-json\/wp\/v2\/comments?post=2997"}],"version-history":[{"count":0,"href":"https:\/\/usatrustedlawyers.com\/blog\/wp-json\/wp\/v2\/posts\/2997\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/usatrustedlawyers.com\/blog\/wp-json\/wp\/v2\/media\/2998"}],"wp:attachment":[{"href":"https:\/\/usatrustedlawyers.com\/blog\/wp-json\/wp\/v2\/media?parent=2997"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/usatrustedlawyers.com\/blog\/wp-json\/wp\/v2\/categories?post=2997"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/usatrustedlawyers.com\/blog\/wp-json\/wp\/v2\/tags?post=2997"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}