Verified case 1 of 3
Marriott International, Inc.
- Date
- 2024-10-09
- Amount
- $52 million settlement; New Jersey will receive just over $1.3 million
- Legal basis
- Data breach laws and consumer protection laws, including the New Jersey Consumer Fraud Act
Why the action was brought
States alleged Marriott misrepresented how it protected consumers’ personal information and failed to use adequate cybersecurity safeguards. Intruders accessed Starwood’s guest reservation database from 2014 to 2018, exposing contact information, gender, dates of birth, reservation information, preferences, passport numbers, and payment-card information. About 131.5 million Americans were impacted; a second incident exposed over 5.2 million guest records.