An error occurred while fetching the data.
Error details: Error: INTERNAL_ERROR for 34b97d68-53be-e4dc-e560-531c588fbcaf: {"response":{"errors":[{"message":"INTERNAL_ERROR for 34b97d68-53be-e4dc-e560-531c588fbcaf","locations":[{"line":93,"column":7}],"path":["articlePackages"],"extensions":{"classification":"INTERNAL_ERROR"}}],"data":{"articleData":{"uri":"/2024/10/09/marriott-to-pay-52m-upgrade-cybersecurity-to-settle-probes-into-3-big-breaches-411-32705/","canonicalUrl":"https://www.law.com/corpcounsel/2024/10/09/marriott-to-pay-52m-upgrade-cybersecurity-to-settle-probes-into-3-big-breaches","generatedId":"hee45gfkdi","naturalId":"blogAndPostId/blog/post/411-32705","recombeeId":"411-32705","type":"ARTICLE","postFormat":"news","kickerPresentedBy":{"label":"","value":""},"breadcrumb":[],"presentedBy":"","title":"Marriott to Pay $52 Million, Upgrade Cybersecurity, to Settle Probes into Three Big Breaches","readtime":"3","timeToRead":"3 minute","prettyModified":"October 09, 2024 at 09:21 PM","prettyDateTime":"October 09, 2024 at 02:33 PM","needToKnow":[],"byline":"Maria Dinzeo","nofollow":false,"showDisclaimer":true,"authors":[{"name":"Maria Dinzeo","description":"Maria Dinzeo is a San Francisco-based journalist covering the intersection of technology and the law, with a focus on AI, privacy and cybersecurity.","imageLarge":"https://secure.gravatar.com/avatar/670092fdd19abfec5455df7339bb59b3?s=136&d=mm&r=g","webUrl":"/author/profile/maria-dinzeo/"}],"publication":"Treasury and Risk","kicker":"News","kickerNode":[{"name":"News","slug":"news-kicker","uri":"/news/","sectionName":"News"}],"prettyDate":"October 09, 2024","pubDate":"2024-10-09 14:33:42.000","modifiedDate":"2024-10-09 21:21:38:418","isDownload":"false","primaryCategory":{"channelName":"","sectionName":"","name":"","uri":"","slug":"","channelUri":""},"tags":["canonical:https://www.law.com/corpcounsel/2024/10/09/marriott-to-pay-52m-upgrade-cybersecurity-to-settle-probes-into-3-big-breaches"],"image":{"uri":"https://images.treasuryandrisk.com/contrib/content/uploads/sites/411/2024/10/Boca-Raton-Marriott-at-Boca-Center-767x633.jpg","width":"767","height":"633","alt":""},"embed1":"","embed2":"","summary":"\"Marriott's poor security practices led to multiple breaches affecting hundreds of millions of customers,\" according to the FTC.","categories":[{"name":"News","uri":"/news/","channelName":"Kicker"},{"name":"Cybersecurity","uri":"/technology/cybersecurity/","channelName":"Technology"}],"allCategories":[{"sectionName":"News","channelName":"Kicker"},{"sectionName":"Cybersecurity","channelName":"Technology"}],"bodyArray":["<p><figure id=\"attachment_126085\" align=\"alignleft\" width=\"767\"> <img class=\"size-full wp-image-126085\" src=\"//images.treasuryandrisk.com/contrib/content/uploads/sites/390/2024/10/Boca-Raton-Marriott-at-Boca-Center-767x633.jpg\" alt=\"\" width=\"767\" height=\"633\"> Two of the cyberattacks began at Starwood in 2014, two years before Marriott bought it for $13 billion. Photo: PR Newswire </figure> </p>","<p>The Federal Trade Commission (FTC) has ordered Marriott International and its subsidiary Starwood Hotels & Resorts Worldwide to implement a \"comprehensive information security program\" after the hotel giant suffered three major data breaches from 2014 to 2020 that exposed the personal information of 344 million customers worldwide.</p>","<p>In a <a href=\"https://portal.ct.gov/ag/press-releases/2024-press-releases/multistate-settlement-with-marriott-for-data-breach-of-starwood-guest-reservation-database\" target=\"_blank\">separate settlement</a> announced Wednesday—which involved all 50 state attorneys general—Marriott agreed to pay $52 million in penalties in connection with two of the breaches, which ran from 2014 to 2018 and exposed 131 million Starwood guest records.</p>","<div class=\"paywall-content\"><p>The enforcement actions highlight the cybersecurity risks companies face when they make large acquisitions, and serve as a stark reminder not to let inherited vulnerabilities go unnoticed. Two of the three breaches occurred at Starwood and began before Marriott bought its lodging rival for $13 billion in 2016, with one going undetected for 14 months and the other going undetected until 2018.</p>","<p>In connection with the FTC settlement, the agency released a <a href=\"//www.ftc.gov/system/files/ftc_gov/pdf/1923022marriottcomplaint.pdf\" target=\"_blank\">complaint</a> and <a href=\"//www.ftc.gov/system/files/ftc_gov/pdf/1923022marriottacco.pdf\" target=\"_blank\">consent order</a> alleging that Marriott misled customers by claiming to have appropriate data security measures in place while, in reality, the hotel chain did not. In fact, Marriott and Starwood failed to implement proper password controls, access controls, or firewall protections, and also neglected to patch outdated software, properly log and monitor their network environments, or use adequate multifactor authentication, according to the FTC.</p>","<p>\"Marriott's poor security practices led to multiple breaches affecting hundreds of millions of customers,\" Samuel Levine, director of the FTC's Bureau of Consumer Protection, said in a statement Wednesday. \"The FTC's action today, in coordination with our state partners, will ensure that Marriott improves its data security practices in hotels around the globe.\"</p>","<p>As part of the FTC settlement, Marriott and Starwood must:</p> <ul> <li>Accurately represent how they handle and protect personal information.</li> <li>Limit how long they keep personal data to only what is necessary, and explain why the information is collected and retained.</li> <li>Create and maintain a comprehensive information security program, certifying compliance to the FTC every year for the next 20 years.</li> <li>Offer a way for customers to review unauthorized activity in loyalty accounts and return any stolen points.</li> <li>Provide a link for customers to request deletion of their personal information.</li> </ul> <p>In a statement, Marriott said that it has already started improving its data privacy and security programs. It is now offering U.S. customers a way to request that their personal information be deleted, providing an online portal for Marriott Bonvoy members to report suspicious activity in their loyalty accounts, and rolling out a multifactor authentication option for Marriott Bonvoy accounts.</p>","<p>\"Protecting guests' personal data remains a top priority for Marriott,\" the company said. \"These resolutions reaffirm the company's continued focus on, and significant investments in, maintaining and adapting programs and systems to assess, identify, and manage risks from evolving cybersecurity threats.\"</p>","<p>The FTC and states said they worked jointly on the probe. The FTC said its settlement does not include a civil penalty because it lacks the legal authority to obtain one in this case.</p> <hr> <hr> <p>From: <a href=\"https://www.law.com/corpcounsel/\" target=\"_blank\">Corporate Counsel</a></p></div>"],"slides":[],"video":""},"articlePackages":null,"youmightlike":[{"uri":"/2025/07/10/fed-minutes-highlight-split-over-tariffs-impact-on-inflation/","title":"Fed Minutes Highlight Split over Tariffs’ Impact on Inflation","byline":"Amara Omeokwe","prettyDate":"July 10, 2025","readtime":"4","image":{"uri":"https://k2-prod-alm.s3.us-east-1.amazonaws.com/brightspot/d0/69/75538eda469eb626442e648ae188/fed-resize-jpeg.jpeg","width":"620","height":"372"},"summary":"Ten of 19 officials expect to enact at least two interest rate cuts by year-end, but seven policymakers plan on no cuts at all in 2025."},{"uri":"/2025/07/10/ntt-closes-record-bond-deal/","title":"NTT Closes Record Bond Deal","byline":"Finbarr Flynn and Caleb Mutua","prettyDate":"July 10, 2025","readtime":"3","image":{"uri":"https://k2-prod-alm.s3.us-east-1.amazonaws.com/brightspot/81/51/db0461da4a8199edf0ffadd2fb03/071025-bloomberg-ntt.jpg","width":"1200","height":"800"},"summary":"The Japanese telecom’s $17.7 billion in dollar and euro bonds marks the biggest-ever offering of foreign bonds by an Asian corporate."},{"uri":"/2025/07/09/us-immigration-policy-may-hit-economy-hard/","title":"U.S. Immigration Policy May Hit Economy Hard","byline":"Catarina Saraiva","prettyDate":"July 09, 2025","readtime":"2","image":{"uri":"https://k2-prod-alm.s3.us-east-1.amazonaws.com/brightspot/58/76/5fccfb7d43edb6e1addd1c48fd91/070925-bloomberg-immigrant.jpg","width":"1200","height":"800"},"summary":"Newly released Fed study projects that the Trump administration’s approach to immigration and deportation will reduce U.S. GDP growth by nearly 1 percentage point this year."},{"uri":"/2025/07/07/tariff-deadline-moved-to-august-1/","title":"Tariff Deadline Moved to August 1","byline":"Brendan Murray","prettyDate":"July 07, 2025","readtime":"4","image":{"uri":"https://k2-prod-alm.s3.us-east-1.amazonaws.com/brightspot/fc/2b/a7ad96ef45ba9fce5ab89af01deb/070725-bloomberg-trump.jpg","width":"1200","height":"800"},"summary":"Since April, the Trump administration has warned that its “Liberation Day” tariffs would take effect this Wednesday for countries failing to secure a trade agreement, but now officials are signaling trading partners will have until August 1."},{"uri":"/2025/07/07/junk-loan-market-hits-stumbling-block/","title":"Junk Loan Market Hits Stumbling Block","byline":"Claire Ruckin, Abhinav Ramnarayan and Rachel Graf","prettyDate":"July 07, 2025","readtime":"4","image":{"uri":"","width":"","height":""},"summary":"After a pre-summer frenzy in junk loans, the market has started to overheat, prompting investors to get a bit more picky about deals."},{"uri":"/2025/07/03/powell-reiterates-fed-would-have-already-cut-rates-this-year-if-not-for-tariffs/","title":"Powell Reiterates Fed Would Have Already Cut Rates This Year, If Not for Tariffs","byline":"Amara Omeokwe","prettyDate":"July 03, 2025","readtime":"4","image":{"uri":"https://images.treasuryandrisk.com/contrib/content/uploads/sites/412/2019/07/Powell_Jerome_Glasses_BB_MI800.jpg","width":"800","height":"451"},"summary":""}],"readnext":{"contents":[{"uri":"/2025/07/10/ntt-closes-record-bond-deal/","title":"NTT Closes Record Bond Deal","byline":"Finbarr Flynn and Caleb Mutua","summary":"The Japanese telecom’s $17.7 billion in dollar and euro bonds marks the biggest-ever offering of foreign bonds by an Asian corporate.","prettyDate":"July 10, 2025","kicker":"News","image":{"uri":"https://k2-prod-alm.s3.us-east-1.amazonaws.com/brightspot/81/51/db0461da4a8199edf0ffadd2fb03/071025-bloomberg-ntt.jpg","width":"1200","height":"800"},"breadcrumb":[],"primaryCategory":{"name":"","uri":"","channelName":"","channelUri":""},"allCategories":[{"channelName":"Corporate Finance","sectionName":"Corporate Borrowing & Debt","slug":"corporate-borrowing-debt","channelUri":"corporate-finance"},{"channelName":"Kicker","sectionName":"News","slug":"news-kicker","channelUri":""}]},{"uri":"/2025/07/10/corporate-optimism-hits-lowest-level-since-2023/","title":"Corporate Optimism Hits Lowest Level Since 2023","byline":"T&R Staff","summary":"Global business leaders expect their operating margins, capex, and long-term borrowing to shrink this quarter.","prettyDate":"July 10, 2025","kicker":"Analysis","image":{"uri":"https://images.treasuryandrisk.com/contrib/content/uploads/sites/411/2024/05/2013-10-22-Global.jpg","width":"1180","height":"889"},"breadcrumb":[],"primaryCategory":{"name":"","uri":"","channelName":"","channelUri":""},"allCategories":[{"channelName":"Kicker","sectionName":"Analysis","slug":"analysis","channelUri":""}]},{"uri":"/2025/07/03/powell-reiterates-fed-would-have-already-cut-rates-this-year-if-not-for-tariffs/","title":"Powell Reiterates Fed Would Have Already Cut Rates This Year, If Not for Tariffs","byline":"Amara Omeokwe","summary":"","prettyDate":"July 03, 2025","kicker":"News","image":{"uri":"https://images.treasuryandrisk.com/contrib/content/uploads/sites/412/2019/07/Powell_Jerome_Glasses_BB_MI800.jpg","width":"800","height":"451"},"breadcrumb":[],"primaryCategory":{"name":"","uri":"","channelName":"","channelUri":""},"allCategories":[{"channelName":"Financial Risk","sectionName":"Interest Rates","slug":"interest-rates","channelUri":"financial-risk"},{"channelName":"Kicker","sectionName":"News","slug":"news-kicker","channelUri":""}]},{"uri":"/2025/07/09/us-immigration-policy-may-hit-economy-hard/","title":"U.S. Immigration Policy May Hit Economy Hard","byline":"Catarina Saraiva","summary":"Newly released Fed study projects that the Trump administration’s approach to immigration and deportation will reduce U.S. GDP growth by nearly 1 percentage point this year.","prettyDate":"July 09, 2025","kicker":"News","image":{"uri":"https://k2-prod-alm.s3.us-east-1.amazonaws.com/brightspot/58/76/5fccfb7d43edb6e1addd1c48fd91/070925-bloomberg-immigrant.jpg","width":"1200","height":"800"},"breadcrumb":[],"primaryCategory":{"name":"","uri":"","channelName":"","channelUri":""},"allCategories":[{"channelName":"Global Markets","sectionName":"Economy","slug":"economy-global-markets","channelUri":"global-markets"},{"channelName":"Kicker","sectionName":"News","slug":"news-kicker","channelUri":""}]},{"uri":"/2025/07/07/junk-loan-market-hits-stumbling-block/","title":"Junk Loan Market Hits Stumbling Block","byline":"Claire Ruckin, Abhinav Ramnarayan and Rachel Graf","summary":"After a pre-summer frenzy in junk loans, the market has started to overheat, prompting investors to get a bit more picky about deals.","prettyDate":"July 07, 2025","kicker":"News","image":{"uri":"","width":"","height":""},"breadcrumb":[],"primaryCategory":{"name":"","uri":"","channelName":"","channelUri":""},"allCategories":[{"channelName":"Kicker","sectionName":"News","slug":"news-kicker","channelUri":""}]}]}},"extensions":{"DateTime":"2025-07-13T02:31:30.547249221","ResponseTime":"?","AuthorizedUser":false,"AlmContext":"AlmContext{clientIP='10.0.253.253', internalIP='true', origin='', authorizedUser='false', Chinchilla, userAccount='null', UCID=null, ipAccount='null', olyEncId='null'}","NavServiceResponse":{"message":"No Content","action":"show-404","data":"","placResultsPublic":null},"DebuggingData":null,"UsedCache":"true","DataUrl":"http://ml2.alm.com:9216/bff-services/content/get-you-may-like-for-content.xqy?naturalId=/2024/10/09/marriott-to-pay-52m-upgrade-cybersecurity-to-settle-probes-into-3-big-breaches-411-32705/&site=www.treasuryandrisk.com&total="},"status":200,"headers":{}},"request":{"query":"\n####\n####\n# QUERY\n# ROUTE:/2024/10/09/marriott-to-pay-52m-upgrade-cybersecurity-to-settle-probes-into-3-big-breaches-411-32705/\n####\n\n\nquery TreasuryandRisk__view_article_no_sitedir{articleData:\n getContent(naturalId: \"/2024/10/09/marriott-to-pay-52m-upgrade-cybersecurity-to-settle-probes-into-3-big-breaches-411-32705/\", site:\"treasuryandrisk.com\") {\n uri\n canonicalUrl\n generatedId\n naturalId\n recombeeId\n type\n postFormat\n kickerPresentedBy {\n \t\t label\n \t\t value\n \t\t}\n breadcrumb{\n name\n \t\turi\n }\n presentedBy\n title\n readtime\n timeToRead\n prettyModified\n prettyDateTime\n needToKnow\n byline\n nofollow\n showDisclaimer\n authors {\n name\n description\n imageLarge\n webUrl\n }\n publication\n kicker\n kickerNode {\n name\n slug\n uri\n sectionName\n }\n prettyDate\n prettyDateTime\n pubDate\n modifiedDate\n isDownload\n primaryCategory {\n channelName\n sectionName\n name\n uri\n slug\n channelUri\n }\n tags\n image {\n uri\n width\n height\n alt\n }\n embed1\n embed2\n summary\n categories {\n name\n uri\n channelName\n }\n allCategories {\n sectionName\n channelName\n } \n bodyArray\n slides {\n title\n image\n caption\n height\n width\n }\n video\n\n }\n articlePackages:\n getPackagesForArticle(docId: \"/2024/10/09/marriott-to-pay-52m-upgrade-cybersecurity-to-settle-probes-into-3-big-breaches-411-32705/\", limit: 3, publication:\"treasuryandrisk.com\") {\n title \n slug\n type \n summary\n cssFile\n navigations {\n name\n link\n }\n articles {\n title\n kicker\n uri\n image {\n uri\n }\n }\n\n \n }\n youmightlike:\n getYouMayLikeForContent(naturalId: \"/2024/10/09/marriott-to-pay-52m-upgrade-cybersecurity-to-settle-probes-into-3-big-breaches-411-32705/\", site:\"treasuryandrisk.com\") {\n uri\n title\n byline\n prettyDate\n readtime\n image {\n uri\n width\n height\n }\n summary\n }\n readnext:\n getStatsList(site:\"treasuryandrisk.com\", topic: \"\", limit: 5, timeframe: \"3days\" ) {\n contents {\n uri\n title\n byline\n summary\n prettyDate\n kicker\n image {\n uri\n width\n height\n }\n breadcrumb{\n name\n \t\turi\n }\n primaryCategory {\n name\n uri\n channelName\n channelUri\n }\n allCategories{\n channelName\n sectionName\n slug\n channelUri\n }\n breadcrumb {\n name\n uri\n }\n }\n\n }\n }"}}