Close Menu
    Facebook X (Twitter) Instagram
    • Home
    • About Us
    • Digital Subscription
    • Advertisement
    • Contact Us
    Facebook X (Twitter) Instagram
    The Tennessee TribuneThe Tennessee Tribune
    Advertise With Us
    • Home
      • COVID-19 Resource Center
        • Dr. Henry Louis Gates’ PSA Radio
      • Featured
    • News
      • State
      • Local
      • National/International News
      • Global
      • Business
        • Commentary
        • Finance
        • Local Business
      • Investigative Stories
        • Affordable Housing
        • DCS Investigation
        • Gentrification
    • Editorial
      • National Politics
      • Local News
      • Local Editorial
      • Political Editorial
      • Editorial Cartoons
      • Cycle of Shame
    • Community
      • History
      • Tennessee
        • Chattanooga
        • Clarksville
        • Knoxville
        • Memphis
      • Public Notices
      • Women
        • Let’s Talk with Ms. June
    • Education
      • College
        • American Baptist College
        • Belmont University
        • Fisk
        • HBCU
        • Meharry
        • MTSU
        • University of Tennessee
        • TSU
        • Vanderbilt
      • Elementary
      • High School
    • Lifestyle
      • Art
      • Auto
      • Tribune Travel
      • Entertainment
        • 5 Questions With
        • Books
        • Events
        • Film Review
        • Local Entertainment
      • Family
      • Food
        • Drinks
      • Health & Wellness
      • Home & Garden
      • Featured Books
    • Religion
      • National Religion
      • Local Religion
      • Obituaries
        • National Obituaries
        • Local Obituaries
      • Faith Commentary
    • Sports
      • MLB
        • Sounds
      • NBA
      • NCAA
      • NFL
        • Predators
        • Titans
      • NHL
      • Other Sports
      • Golf
      • Professional Sports
      • Sports Commentary
      • Metro Sports
    • Media
      • Video
      • Photo Galleries
      • Take 10
      • Trending With The Tribune
    • Classified
    • Obituaries
      • Local Obituaries
      • National Obituaries
    The Tennessee TribuneThe Tennessee Tribune
    Tennessee

    TN AG Skrmetti Announces $52 Million Multistate Settlement with Marriott for Data Breach of Starwood Guest Reservation Database

    Brandon SawyersBy Brandon SawyersOctober 12, 2024Updated:October 12, 2024No Comments4 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    NASHVILLE – Attorney General Jonathan Skrmetti announced today that a coalition of 50 Attorneys General has reached a settlement with Marriott International, Inc. as the result of an investigation into a large multi-year data breach of one of its guest reservation databases. The Federal Trade Commission, which has been coordinating closely with the states throughout this investigation, has reached a parallel settlement with Marriott. Under the settlement with the Attorneys General, Marriott has agreed to strengthen its data security practices using a dynamic risk-based approach, provide certain consumer protections, and make a $52 million payment to states. Tennessee will receive $919,043.00 from the settlement.

    “When Tennesseans submit their personal information to a company, they expect that to stay private,” said Tennessee Attorney General Jonathan Skrmetti. “A breach of this magnitude is not just a violation of privacy; it’s a violation of trust. Our Office is proud to have worked alongside Connecticut and 48 attorneys general to hold Marriott International accountable and ensure protections for consumers’ personal data. Affected Tennesseans will receive specific protections going forward, including data deletion, account monitoring, and an option for multifactor authentication on any Marriott account.”

    Marriott acquired Starwood in 2016 and took control of the Starwood computer network in 2016.  However, from July 2014 until September 2018, intruders in the system went undetected. This led to the breach of 131.5 million guest records pertaining to customers in the United States. The impacted records included contact information, gender, dates of birth, legacy Starwood Preferred Guest information, reservation information, and hotel stay preferences, as well as a limited number of unencrypted passport numbers and unexpired payment card information.

    Shortly after the breach of the Starwood database was announced, a coalition of 50 Attorneys General launched a multi-state investigation into the breach. Today’s settlement resolves allegations by the Attorneys General that Marriott violated state consumer protection laws, personal information protection laws, and, where applicable, breach notification laws by failing to implement reasonable data security and remediate data security deficiencies, particularly when attempting to use and integrate Starwood into its systems.

    Under the terms of the settlement, Marriott has agreed to strengthen and continually improve its cybersecurity practices. Some of the specific measures include:

    • Implementation of a comprehensive Information Security Program. This includes new overarching security program mandates, such as incorporating zero-trust principles, regular security reporting to the highest levels within the company, including the Chief Executive Officer, and enhanced employee training on data handling and security.
    • Data minimization and disposal requirements, which will lead to less consumer data being collected and retained.
    • Specific security requirements with respect to consumer data, including component hardening, conducting an asset inventory, encryption, segmentation to limit an intruder’s ability to move across a system, patch management to ensure that critical security patches are applied in a timely manner, intrusion detection, user access controls, and logging and monitoring to keep track of movement of files and users within the network.  
    • Increased vendor and franchisee oversight, with a special emphasis on risk assessments for “Critical IT Vendors,” and clearly outlined contracts with cloud providers.
    • In the future, if Marriott acquires another entity, it must timely further assess the acquired entity’s information security program and develop plans to address identified gaps or deficiencies in security as part of the integration into Marriott’s network.
    • An independent third-party assessment of Marriott’s information security program every two years for a period of 20 years for additional security oversight.

    These settlement terms are grounded in a well-developed risk-based approach in which Marriott not only needs to conduct an annual enterprise level risk assessment, but it must also perform risk analyses throughout the year for changes to security controls. Those ongoing risk assessments must address the criteria of “harm to others” – which would include potential harm to consumers.

    As part of the settlement, Marriott will give consumers specific protections, including a data deletion option, even if consumers do not currently have that right under state law. Marriott must offer multi-factor authentication to consumers for their loyalty rewards accounts, such as Marriott Bonvoy, as well as reviews of those accounts if there is suspicious activity.

    Joining Tennessee in this settlement are Alaska, the Executive Committee of Alabama, Arkansas, Arizona, California, Colorado, Connecticut, Delaware, the District of Columbia, Florida, Georgia, Hawaii, Idaho, Illinois, Indiana, Iowa, Kansas, Kentucky, Louisiana, Massachusetts, Maryland, Maine, Michigan, Minnesota, Missouri, Mississippi, Montana, North Carolina, North Dakota, Nebraska, New Hampshire, New Jersey, New Mexico, Nevada, New York, Ohio, Oklahoma, Oregon, Pennsylvania, Rhode Island, South Carolina, South Dakota, Texas, Utah, Virginia, Vermont, Washington, Wisconsin, West Virginia, Wyoming, and Vermont.

    You can read the full settlement here.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Brandon Sawyers

    Related Posts

    Get Ready for the Return of 17-Year Cicadas Most East Tennessee Counties Will See and Hear Brood XIV Adult Cicadas

    April 16, 2025

    Tennessee Selects Carrum Health to Improve Value in Specialty Care Spending for State Employees

    April 16, 2025

    Death Row Prisoners Ask Governor Lee to Halt Tennessee Executions Until 2026 to Ensure Judicial Review of New Protocol

    April 16, 2025

    TDMHSAS AWARDS $5,200,000 TO CREATE AFFORDABLE HOUSING FOR PEOPLE LIVING WITH BEHAVIORAL HEALTH CHALLENGES

    April 15, 2025

    Tennessee AG Skrmetti Seeks Dissolution of Transplant Charity for Misleading Patients About Donated Funds

    April 14, 2025

    Tennessee Human Rights Commission to Host Fair Housing Summit April 29

    April 6, 2025

    Comments are closed.

    Business

    Target Boycotts and its Effect on Both Sides of the Black Dollar

    May 6, 2025

    FedEx to Launch FedEx Easy Returns at 3,000 Locations Across the US, Supported by Blue Yonder

    May 2, 2025

    Best Lawyers® Names Bailey, Hargrove, Haynes, and Stakely Lawyers of the Year

    April 24, 2025
    1 2 3 … 382 Next
    Education
    HBCU

    TSU Honors New Generation of Leaders at Spring Commencement Celebration

    By Emmanuel FreemanMay 8, 2025

    NASHVILLE, Tenn. – (TSU News Service)– In a celebration steeped in legacy and hope, Tennessee…

    Fisk University Honors the Class of 2025 with Baccalaureate and Commencement Ceremonies

    April 26, 2025

    TSU’s Spring Commencement Ceremonies to Feature Inspiring Keynote Speakers

    April 24, 2025

    TSU’s Dr. Robbie K. Melton Named a 2025 Leading Woman in AI

    April 24, 2025
    The Tennessee Tribune
    Facebook X (Twitter) Instagram
    • About Us
    • Digital Subscription
    • Store
    • Advertise With Us
    • Contact
    © 2025 The Tennessee Tribune - Site Designed by No Regret Media.

    Type above and press Enter to search. Press Esc to cancel.

    Our Spring Sale Has Started

    You can see how this popup was set up in our step-by-step guide: https://wppopupmaker.com/guides/auto-opening-announcement-popups/