Thursday, 26 December 2024
25 C
Singapore

Marriott and Starwood hotels urged to strengthen data security measures

The FTC ordered Marriott and Starwood to improve data security after breaches exposed the information of 344M customers with new policies and transparency.

The Federal Trade Commission (FTC) has finalised an order requiring Marriott International and its subsidiary Starwood Hotels to enhance their data practices significantly. This follows a series of major data breaches that compromised sensitive customer information, including passport details and payment card data.

Major breaches highlight security lapses

The breaches, identified in 2015, 2018, and 2020, exposed the personal information of over 344 million customers globally. The most severe incident allowed hackers to remain undetected within the systems for four years, from 2018 to 2022. Another breach lasted 14 months before detection.

The FTC accused Marriott and Starwood of failing to implement adequate security measures, leaving their systems vulnerable. Shortcomings included poor password , weak firewall practices, and failure to update outdated software and systems. The companies were criticised for misleading customers by claiming “reasonable and appropriate data security” measures.

Strengthening security and customer transparency

Marriott and Starwood must implement comprehensive data security policies as part of the FTC’s directive. These include:

  • Retaining customer information only for as long as necessary.
  • Providing a public link for US-based customers to request the deletion of personal information tied to their email addresses or loyalty accounts.

Additionally, the companies are barred from misrepresenting how they handle personal data. They must be transparent about their processes for collecting, maintaining, using, deleting, and protecting consumer information.

The FTC order also mandates that Marriott and Starwood:

  • Maintain compliance records.
  • Undergo periodic inspections by the FTC.
  • Comply with these requirements for the next 20 years.

This isn’t the only financial penalty Marriott has faced. On the same day the FTC announced the charges, Marriott agreed to a $52 million settlement with the Connecticut Attorney General’s office.

Hotels as prime hacking targets

Hotels remain attractive targets for cyberattacks due to the vast amount of sensitive information they collect. The hospitality industry has faced increased scrutiny following high-profile incidents, such as the 2023 ransomware attack on MGM Resorts. This breach caused significant disruptions, including delayed check-ins and operations reverting to pen-and-paper methods.

FTC Chair Lina Khan emphasised the importance of robust cybersecurity in the hospitality sector, highlighting the widespread impact such breaches can have on customers and business operations.

With the FTC’s oversight now in place, Marriott and Starwood are expected to adopt stricter protocols to protect consumer data, helping restore customer trust in their brands.

Hot this week

Chinese EV maker Nio introduces Firefly brand to rival Mini Cooper and Smart

Nio unveils the affordable Firefly EV to rival Mini and Smart alongside its luxury ET9 sedan, combining innovation and style for global markets.

Agentforce 2.0 revolutionises digital labour for enterprises

Salesforce launches Agentforce 2.0, a digital labour platform enabling enterprises to scale with AI agents, improving productivity and customer support.

China’s CATL unveils EV chassis designed to survive high-speed crashes

CATL unveils a new EV chassis that can withstand 120km/h crashes, offering a 1,000km range and faster production times for premium automakers.

US to blacklist Chinese company linked to Huawei chip scandal

The US plans to blacklist Sophgo, a Chinese firm tied to Huawei’s AI chip scandal, in a crackdown on tech linked to national security risks.

LG introduces 2025 QNED Evo with groundbreaking technology

LG unveils its 2025 QNED Evo TV lineup featuring new AI technologies and true wireless 4K viewing, enhancing the premium television viewing experience.

2025 could be a pivotal year for AI, as global CFOs express concerns over ROI

A global survey of CFOs reveals growing concerns over AI ROI, with many planning to reduce AI spending if results aren't visible by 2025.

Russia bans cryptocurrency mining in ten regions due to energy concerns

Russia bans crypto mining in ten regions from January 2024 due to concerns over high energy consumption and the industry's impact on resources.

CES 2025: What to expect from AMD, NVIDIA, Hyundai, and more in Las Vegas

Discover what’s coming to CES 2025, including AI advancements, gaming GPUs, and smart tech from NVIDIA, AMD, Hyundai, and more in Las Vegas.

China’s CATL unveils EV chassis designed to survive high-speed crashes

CATL unveils a new EV chassis that can withstand 120km/h crashes, offering a 1,000km range and faster production times for premium automakers.

Related Articles

Popular Categories