Verified case 1 of 3
Marriott International, Inc.
- Date
- 2024-10-09
- Amount
- $52 million payment to states; Connecticut will receive $1,992,130.00
- Legal basis
- State consumer protection laws, personal information protection laws, and, where applicable, breach notification laws
Why the action was brought
Marriott failed to implement reasonable data security and remediate data security deficiencies while attempting to use and integrate Starwood into its systems. Intruders went undetected from July 2014 through September 2018, resulting in the exposure of 131.5 million U.S. guest records, including contact information, birth dates, reservation data, preferences, passport numbers, and payment card information.