Thursday, 1 May 2025
30.1 C
Singapore
35.6 C
Thailand
26.4 C
Indonesia
28.8 C
Philippines

Marriott and Starwood hotels urged to strengthen data security measures

The FTC ordered Marriott and Starwood to improve data security after breaches exposed the information of 344M customers with new policies and transparency.

The Federal Trade Commission (FTC) has finalised an order requiring Marriott International and its subsidiary Starwood Hotels to enhance their data security practices significantly. This follows a series of major data breaches that compromised sensitive customer information, including passport details and payment card data.

Major breaches highlight security lapses

The breaches, identified in 2015, 2018, and 2020, exposed the personal information of over 344 million customers globally. The most severe incident allowed hackers to remain undetected within the systems for four years, from 2018 to 2022. Another breach lasted 14 months before detection.

The FTC accused Marriott and Starwood of failing to implement adequate security measures, leaving their systems vulnerable. Shortcomings included poor password management, weak firewall practices, and failure to update outdated software and systems. The companies were criticised for misleading customers by claiming “reasonable and appropriate data security” measures.

Strengthening security and customer transparency

Marriott and Starwood must implement comprehensive data security policies as part of the FTC’s directive. These include:

  • Retaining customer information only for as long as necessary.
  • Providing a public link for US-based customers to request the deletion of personal information tied to their email addresses or loyalty accounts.

Additionally, the companies are barred from misrepresenting how they handle personal data. They must be transparent about their processes for collecting, maintaining, using, deleting, and protecting consumer information.

The FTC order also mandates that Marriott and Starwood:

  • Maintain compliance records.
  • Undergo periodic inspections by the FTC.
  • Comply with these requirements for the next 20 years.

This isn’t the only financial penalty Marriott has faced. On the same day the FTC announced the charges, Marriott agreed to a $52 million settlement with the Connecticut Attorney General’s office.

Hotels as prime hacking targets

Hotels remain attractive targets for cyberattacks due to the vast amount of sensitive information they collect. The hospitality industry has faced increased scrutiny following high-profile incidents, such as the 2023 ransomware attack on MGM Resorts. This breach caused significant disruptions, including delayed check-ins and operations reverting to pen-and-paper methods.

FTC Chair Lina Khan emphasised the importance of robust cybersecurity in the hospitality sector, highlighting the widespread impact such breaches can have on customers and business operations.

With the FTC’s oversight now in place, Marriott and Starwood are expected to adopt stricter protocols to protect consumer data, helping restore customer trust in their brands.

Hot this week

Ghost of Yotei is set to launch on PS5 this October with a new trailer and details

Ghost of Yotei arrives on PS5 this October with a new trailer, a thrilling story, and multiple game editions, including exclusive extras.

Freepik launches new AI image tool built on licensed, safe content

Freepik releases F Lite, a new AI image model trained on licensed images. This tool offers developers an ethical and open-source option.

AI-driven bots now dominate global web traffic, posing new cybersecurity challenges

AI-fuelled bots now make up 51% of web traffic, with rising attacks on APIs and critical industries, says 2025 Imperva Bad Bot Report.

Early cancer detection startup Craif raises US$22M to expand into the U.S.

Craif raises $22M to expand its microRNA early cancer detection technology into the U.S., aiming to make testing simple and accessible.

Snapchat drops plans for simplified app, tests new five-tab layout instead

Snapchat has dropped its simplified app redesign and is testing a new five-tab layout to improve user experience and content discovery.

Garmin introduces Instinct 3 – Tactical Edition smartwatch in Singapore

Garmin launches the Instinct 3 – Tactical Edition in Singapore, combining durability, tactical tools, health tracking, and solar power.

Verizon report reveals 80% of APAC breaches caused by system intrusions

System intrusions caused 80% of data breaches in APAC, according to Verizon’s 2025 report, with malware and ransomware threats on the rise.

Asia Pacific’s AI progress held back by network limitations, says IDC report

APAC’s AI ambitions are limited by poor network infrastructure, with 94% of firms saying their networks can’t support large-scale AI projects.

Borderlands 4 reveals first look at new gameplay and characters

Borderlands 4 reveals extended gameplay, two new Vault Hunters, and co-op features ahead of its launch on 12 September 2025.

Related Articles

Popular Categories