Court Rules
All enforcement actions
SettlementHigh RiskMultistate

TX AG Settles Marriott Data Breach for $3.5M, Mandates Zero-Trust

Marriott International, Inc.October 9, 2024Texas Attorney General

Penalty Amount

$3,500,000

Consumers Affected

131,000,000

Summary

Texas Attorney General Ken Paxton secured a $3.5 million settlement with Marriott International, Inc. following an investigation into a data breach of the company’s reservation database that exposed 131 million U.S. guest records. The breach included sensitive customer information such as contact details, dates of birth, unencrypted passport numbers, and unexpired payment card information. Marriott is required to implement enhanced data security measures, including zero-trust principles and regular security reporting to its CEO, as part of the settlement.

Remedy

Marriott must pay $52 million total to 50 participating states, including $3.5 million to Texas. The company is subject to an Agreed Final Judgment requiring implementation of a comprehensive data security program incorporating zero-trust principles, regular security reports to its CEO, and enhanced employee data handling training.

Monetary PenaltyInjunctionCompliance Program

Contract Impact

In-house legal teams should review vendor agreements with hospitality and service providers to ensure robust data security clauses mandating zero-trust principles, regular security reporting to executive leadership, and employee training on data handling. Contracts should include clear breach notification requirements, obligations to safeguard sensitive personal information (including passport numbers and payment card data), and audit rights to verify compliance with security mandates. Teams should also update data processing agreements to require vendors to implement risk-based security programs aligned with state data protection laws.

Contract Search Terms

data security programzero-trust principlesbreach notificationguest record protectionpayment card data securitypassport information safeguardingdata security trainingCEO security reportingpersonal information safeguarding

Laws Cited

Texas law

Violation Types

Entity Details

Entity

Marriott International, Inc.

Also known as: Marriott

Industry

Other

Multistate Coalition

49 other U.S. state Attorneys General

Official Sources

Source Evidence

Entity Name
"Marriott International, Inc."
Fine Amount
"$3.5 million to the State of Texas"
Fine Amount
"$52 million payment to the 50 states participating in this settlement"
Laws Cited
"Texas law is clear that companies in possession of Texans’ personal information have a duty to safeguard that data"
Violation Types
"breach of one of the company’s reservation databases. The breach exposed 131 million guest records pertaining to customers in the United States and these records included contact information, gender, dates of birth, legacy Starwood Preferred Guest information, reservation information, and hotel stay preferences, as well as a limited number of unencrypted passport numbers and unexpired payment card information."
Consumers Affected
"131 million guest records pertaining to customers in the United States"

Related Enforcement Actions

NJ

Marriott International, Inc.

$52.0M

A multistate coalition of 50 attorneys general, including New Jersey, reached a $52 million settlement with Marriott International, Inc. for two data breaches that exposed personal information of over 131 million consumers. The breaches resulted from inadequate cybersecurity practices at Starwood and Marriott networks. The settlement mandates comprehensive security improvements and monetary penalties.

NY

Marriott International, Inc.

$52.0M

A multistate coalition of 50 attorneys general led by New York AG Letitia James reached a $52 million settlement with Marriott International, Inc. over a 2014-2018 data breach of its Starwood subsidiary’s guest reservation database that exposed 131.5 million consumers’ personal information. The breach, which went undetected for four years, compromised contact details, dates of birth, passport numbers, payment card information, and loyalty program data. Marriott is required to overhaul its data security practices, implement new compliance measures, and allow customers to delete their stored data as part of the settlement.

CT

Marriott International, Inc.

$52.0M

A multistate settlement with Marriott International for a data breach affecting 131.5 million guest records. Marriott failed to secure the Starwood network from 2014 to 2018, exposing personal information. The settlement includes a $52 million payment and requires Marriott to implement enhanced cybersecurity measures and consumer protections.

TX

Tris Pharmaceuticals

$7.5M

Texas Attorney General Ken Paxton announced a $7.5 million settlement with Tris Pharmaceuticals over alleged misrepresentations about the efficacy of Dyanavel XR, an ADHD drug marketed for children. The release says the company overstated the drug’s efficacy and directed sales representatives to make misleading claims to doctors, including Medicaid providers.

TX

Plum Organics

Texas Attorney General Ken Paxton announced an agreement with Plum Organics requiring stronger testing and limits for heavy metals in covered baby food products, along with publicly accessible testing results. The release does not state a monetary penalty; the agreement follows an ongoing investigation into baby food manufacturers.

TX

Health Care Service Corporation (including Blue Cross and Blue Shield of Texas)

Texas Attorney General Ken Paxton opened an investigation into Blue Cross and Blue Shield of Texas, its parent Health Care Service Corporation, and related entities over alleged denials or delays of urgent and medically necessary care and potentially burdensome prior authorization requirements. The investigation is ongoing; the Attorney General issued a Civil Investigative Demand to obtain information and assess potential violations of Texas law.