Marriott International and its subsidiary Starwood Hotels will pay $52 million and create a comprehensive information security program as part of settlements for data breaches that impacted over 344 million customers.
The UK Information Commissioner's Office (ICO) intends to fine Marriott International Inc £99,200,396 ($123,705,869 / €110,385,736) for infringing the General Data Protection Regulation (GDPR) according to a press release published today.
Discover all SaaS accounts ever created by anyone in your org, in minutes, along with insights on security risks and spend. Save time, money and effort by curbing SaaS sprawl and automating tasks like offboarding and user access reviews. Free trial.
In November 2018, Marriott announced that there was unauthorized access to their Starwood reservation system & that the data for up to 500 million guests had been compromised. In an update today for this incident, Marriott has lowered the amount of affected victims, but states 5.25 million unencrypted passport numbers were accessed.
Malware is believed to have infiltrated point-of-sale (POS) terminals and compromised customers' payment card information at 20 HEI Hotels & Resorts locations. This malware affected a total of 12 Starwood hotels, six Marriott resorts, and one location of Hyatt and Intercontinental each.