Marriott agrees to pay $52 million settlement, improve data security practices
ID: 253aa9df-fada-5527-84ae-def05a45529f
STIX ID: report--253aa9df-fada-5527-84ae-def05a45529f
Feed Name: CyberScoop
Marriott and Starwood settled with federal and state authorities after multiple breaches between 2014–2020 that exposed hundreds of millions of guest records; attackers used inadequate network controls to deploy keyloggers, remote access trojans and memory-scraping malware across hundreds of systems, resulting in a 339 million-record compromise and additional smaller breaches. The FTC consent order and multistate settlement require comprehensive security improvements including multifactor authentication, patching, logging/monitoring, least-privilege access, breach after-action reporting, and data minimization.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
