Penalty Amount
$3,500,000
Consumers Affected
131,000,000
Texas Attorney General Ken Paxton secured a $3.5 million settlement with Marriott International, Inc. following an investigation into a data breach of the company’s reservation database that exposed 131 million U.S. guest records. The breach included sensitive customer information such as contact details, dates of birth, unencrypted passport numbers, and unexpired payment card information. Marriott is required to implement enhanced data security measures, including zero-trust principles and regular security reporting to its CEO, as part of the settlement.
Marriott must pay $52 million total to 50 participating states, including $3.5 million to Texas. The company is subject to an Agreed Final Judgment requiring implementation of a comprehensive data security program incorporating zero-trust principles, regular security reports to its CEO, and enhanced employee data handling training.
In-house legal teams should review vendor agreements with hospitality and service providers to ensure robust data security clauses mandating zero-trust principles, regular security reporting to executive leadership, and employee training on data handling. Contracts should include clear breach notification requirements, obligations to safeguard sensitive personal information (including passport numbers and payment card data), and audit rights to verify compliance with security mandates. Teams should also update data processing agreements to require vendors to implement risk-based security programs aligned with state data protection laws.
Entity
Marriott International, Inc.
Also known as: Marriott
Industry
Other"Marriott International, Inc."
"$3.5 million to the State of Texas"
"$52 million payment to the 50 states participating in this settlement"
"Texas law is clear that companies in possession of Texans’ personal information have a duty to safeguard that data"
"breach of one of the company’s reservation databases. The breach exposed 131 million guest records pertaining to customers in the United States and these records included contact information, gender, dates of birth, legacy Starwood Preferred Guest information, reservation information, and hotel stay preferences, as well as a limited number of unencrypted passport numbers and unexpired payment card information."
"131 million guest records pertaining to customers in the United States"
$52.0M
A multistate coalition of 50 attorneys general, including New Jersey, reached a $52 million settlement with Marriott International, Inc. for two data breaches that exposed personal information of over 131 million consumers. The breaches resulted from inadequate cybersecurity practices at Starwood and Marriott networks. The settlement mandates comprehensive security improvements and monetary penalties.
$52.0M
A multistate coalition of 50 attorneys general led by New York AG Letitia James reached a $52 million settlement with Marriott International, Inc. over a 2014-2018 data breach of its Starwood subsidiary’s guest reservation database that exposed 131.5 million consumers’ personal information. The breach, which went undetected for four years, compromised contact details, dates of birth, passport numbers, payment card information, and loyalty program data. Marriott is required to overhaul its data security practices, implement new compliance measures, and allow customers to delete their stored data as part of the settlement.
$52.0M
A multistate settlement with Marriott International for a data breach affecting 131.5 million guest records. Marriott failed to secure the Starwood network from 2014 to 2018, exposing personal information. The settlement includes a $52 million payment and requires Marriott to implement enhanced cybersecurity measures and consumer protections.
$7.5M
Texas Attorney General Ken Paxton announced a $7.5 million settlement with Tris Pharmaceuticals over alleged misrepresentations about the efficacy of Dyanavel XR, an ADHD drug marketed for children. The release says the company overstated the drug’s efficacy and directed sales representatives to make misleading claims to doctors, including Medicaid providers.
Texas Attorney General Ken Paxton announced an agreement with Plum Organics requiring stronger testing and limits for heavy metals in covered baby food products, along with publicly accessible testing results. The release does not state a monetary penalty; the agreement follows an ongoing investigation into baby food manufacturers.
Texas Attorney General Ken Paxton opened an investigation into Blue Cross and Blue Shield of Texas, its parent Health Care Service Corporation, and related entities over alleged denials or delays of urgent and medically necessary care and potentially burdensome prior authorization requirements. The investigation is ongoing; the Attorney General issued a Civil Investigative Demand to obtain information and assess potential violations of Texas law.