logo

FTC orders Marriott and Starwood to implement strict data security

ID: 9095a980-41ec-5356-948e-4518f5f405a3

STIX ID: report--9095a980-41ec-5356-948e-4518f5f405a3

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-12-23

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

The FTC has finalized a 20-year order requiring Marriott and Starwood to implement a comprehensive data security program within 180 days after repeated failures left customer data exposed in multiple breaches—most notably a Starwood reservation-database compromise inherited by Marriott that affected approximately 339–344 million guest records, including unencrypted passport numbers. The order mandates encryption, access controls, MFA, monitoring and logging, retention limits, consumer deletion and review mechanisms, biennial independent assessments, and strict breach notification/reporting requirements; Marriott also agreed to a $52 million settlement related to these incidents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.