Open in App
  • Local
  • Headlines
  • Election
  • Sports
  • Lifestyle
  • Education
  • Real Estate
  • Newsletter
  • WTAJ

    Pa. Attorney General reaches $1.6M settlement with hotel, resort

    By Hayden Thompson,

    8 hours ago

    https://img.particlenews.com/image.php?url=4HpZd1_0w0dtW2k00

    HARRISBURG, Pa. (WTAJ) — Attorney General Michelle Henry has joined 50 other generals in a settlement with Marriott International, Inc.

    The settlement will require the hotel and “resort giant” to pay millions after a widespread data breach impacted over 100 million travelers, according to Henry. The breach happened in 2016 as Marriott was acquiring Starwood Hotels and Resorts. Compromised information included dates of birth, passport numbers and payment card information.

    In total, Marriott has agreed to pay $52 million out as a result of the settlement, with $1,685,515 going to Pennsylvania.

    “This massive breach of data could have been catastrophic for numerous consumers — some who had their passport and payment card information exposed due to flimsy safeguards in place at the time,” Attorney General Henry said. “This settlement involves significant financial payment, and also assurance that future risk will be minimized.”

    Get the latest news, weather forecasts and sports stories delivered straight to your inbox! Sign up for our newsletters .

    Marriott also agreed to strengthen and improve its cybersecurity practices. Some of the new measures include:

    • Implementation of a comprehensive Information Security Program. This includes new overarching security program mandates, such as incorporating zero-trust principles, regular security reporting to the highest levels within the company, including the Chief Executive Officer, and enhanced employee training on data handling and security
    • Data minimization and disposal requirements, which will lead to less consumer data being collected and retained
    • An independent third-party assessment of Marriott’s information security program every two years for a period of 20 years for additional security oversight
    • Increased vendor and franchisee oversight, with a special emphasis on risk assessments for “Critical IT Vendors,” and clearly outlined contracts with cloud providers
    Copyright 2024 Nexstar Media Inc. All rights reserved. This material may not be published, broadcast, rewritten, or redistributed.

    For the latest news, weather, sports, and streaming video, head to WTAJ - www.wtaj.com.

    Expand All
    Comments /
    Add a Comment
    YOU MAY ALSO LIKE
    Local News newsLocal News
    The Shenandoah (PA) Sentinel22 days ago

    Comments / 0