Monday, 10 March 2025
25.7 C
Singapore
28.4 C
Thailand
20.4 C
Indonesia
26.5 C
Philippines

Marriott and Starwood hotels urged to strengthen data security measures

The FTC ordered Marriott and Starwood to improve data security after breaches exposed the information of 344M customers with new policies and transparency.

The Federal Trade Commission (FTC) has finalised an order requiring Marriott International and its subsidiary Starwood Hotels to enhance their data security practices significantly. This follows a series of major data breaches that compromised sensitive customer information, including passport details and payment card data.

Major breaches highlight security lapses

The breaches, identified in 2015, 2018, and 2020, exposed the personal information of over 344 million customers globally. The most severe incident allowed hackers to remain undetected within the systems for four years, from 2018 to 2022. Another breach lasted 14 months before detection.

The FTC accused Marriott and Starwood of failing to implement adequate security measures, leaving their systems vulnerable. Shortcomings included poor password management, weak firewall practices, and failure to update outdated software and systems. The companies were criticised for misleading customers by claiming โ€œreasonable and appropriate data securityโ€ measures.

Strengthening security and customer transparency

Marriott and Starwood must implement comprehensive data security policies as part of the FTC’s directive. These include:

  • Retaining customer information only for as long as necessary.
  • Providing a public link for US-based customers to request the deletion of personal information tied to their email addresses or loyalty accounts.

Additionally, the companies are barred from misrepresenting how they handle personal data. They must be transparent about their processes for collecting, maintaining, using, deleting, and protecting consumer information.

The FTC order also mandates that Marriott and Starwood:

  • Maintain compliance records.
  • Undergo periodic inspections by the FTC.
  • Comply with these requirements for the next 20 years.

This isnโ€™t the only financial penalty Marriott has faced. On the same day the FTC announced the charges, Marriott agreed to a $52 million settlement with the Connecticut Attorney Generalโ€™s office.

Hotels as prime hacking targets

Hotels remain attractive targets for cyberattacks due to the vast amount of sensitive information they collect. The hospitality industry has faced increased scrutiny following high-profile incidents, such as the 2023 ransomware attack on MGM Resorts. This breach caused significant disruptions, including delayed check-ins and operations reverting to pen-and-paper methods.

FTC Chair Lina Khan emphasised the importance of robust cybersecurity in the hospitality sector, highlighting the widespread impact such breaches can have on customers and business operations.

With the FTCโ€™s oversight now in place, Marriott and Starwood are expected to adopt stricter protocols to protect consumer data, helping restore customer trust in their brands.

Hot this week

WeChat mini-game advertising sees 113% increase, creating new opportunities for developers

WeChat mini-game ads grew 113% in 2024, opening major growth chances for developers aiming to scale in Chinaโ€™s fast-moving mobile game market.

Trump grants automakers a one-month delay on tariffs to move production to the U.S.

Trump grants automakers a one-month delay on tariffs, urging them to move production from Canada and Mexico to the U.S. before April 2.

Dell and Alienware unveil new monitors in Singapore

Dell launches new monitors in Singapore, including the Pro 14 Plus, Pro 34 Plus, and a 75-inch touch monitor for professional use.

Assassin’s Creed Shadows confirmed for day-one Mac release

Ubisoft confirms that Assassinโ€™s Creed Shadows will launch on Macs from day one, supporting M-series chips. The game will be released on March 20.

Da Nang investment forum 2025 highlights Vietnamโ€™s push to become a financial hub

Da Nang Investment Forum 2025 highlights plans to make Da Nang a financial hub, strengthening economic ties with Singapore and global investors.

Jim Jordan subpoenas YouTube over alleged censorship ties to the Biden administration

Jim Jordan subpoenas Alphabet, seeking documents on YouTubeโ€™s alleged censorship ties to Biden. Google defends its content policies amid scrutiny.

Dell and Alienware unveil new monitors in Singapore

Dell launches new monitors in Singapore, including the Pro 14 Plus, Pro 34 Plus, and a 75-inch touch monitor for professional use.

Microsoft intensifies AI race to rival OpenAI

Microsoft is increasing its AI efforts, developing its models and testing alternatives to OpenAI technology for products like Copilot.

Google co-founder Larry Page reportedly launching AI-driven manufacturing startup

Google co-founder Larry Page is reportedly launching Dynatomics, an AI-driven manufacturing startup that will optimise product design and production.

Related Articles