The Federal Trade Commission (FTC) has ordered Marriott International and its subsidiary Starwood Hotels & Resorts Worldwide to implement a "comprehensive information security program" after the hotel giant suffered three major data breaches from 2014 to 2020 that exposed the personal information of 344 million customers worldwide.
In a separate settlement announced Wednesday—which involved all 50 state attorneys general—Marriott agreed to pay $52 million in penalties in connection with two of the breaches, which ran from 2014 to 2018 and exposed 131 million Starwood guest records.
Complete your profile to continue reading and get FREE access to Treasury & Risk, part of your ALM digital membership.
Your access to unlimited Treasury & Risk content isn’t changing.
Once you are an ALM digital member, you’ll receive:
- Thought leadership on regulatory changes, economic trends, corporate success stories, and tactical solutions for treasurers, CFOs, risk managers, controllers, and other finance professionals
- Informative weekly newsletter featuring news, analysis, real-world case studies, and other critical content
- Educational webcasts, white papers, and ebooks from industry thought leaders
- Critical coverage of the employee benefits and financial advisory markets on our other ALM sites, PropertyCasualty360 and ThinkAdvisor
Already have an account? Sign In Now
*May exclude premium content© 2025 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.