Skip to content

FTC: Marriott and Starwood, data breaches data breach case

US Federal Trade Commission · decided Oct 9, 2024 · Settled

The FTC alleged lax security led to three breaches from 2014 to 2020 affecting more than 344 million customers worldwide.

The case

Regulator
US Federal Trade Commission
Decided
Oct 9, 2024
Status
SettledOrder finalized December 2024.
Outcome
Marriott and Starwood must run a comprehensive security program and let US customers request deletion of their data.

History

1 dated entry
DateEntry
Oct 9, 2024Decision: FTC: Marriott and Starwood, data breaches
WhenCase
Dec 11, 2025Filed 9mo agofiledICO fine: LastPass, 2022 breachDecidedData breachUK Information Commissioner's OfficeGBP 1.2 million
Aug 13, 2025Filed 13mo agofiledIn re Coinbase Customer Data Security Breach LitigationActiveData breachS.D. N.Y.
Jun 17, 2025Filed 15mo agofiledICO fine: 23andMe, genetic data breachDecidedData breachUK Information Commissioner's OfficeGBP 2.31 million
Apr 8, 2025Filed 18mo agofiledIn re PowerSchool Customer Data Security Breach LitigationActiveData breachS.D. Cal.
Jan 15, 2025Filed 20mo agofiledFTC: GoDaddy, hosting securitySettledData breachUS Federal Trade Commission
Dec 17, 2024Filed 21mo agofiledDPC fine: Meta, 2018 Facebook breachDecidedData breachIrish DPCEUR 251 million
Oct 8, 2024Filed 24mo agofiledIn re Snowflake Data Security Breach LitigationActiveData breachD. Mont.
Sep 27, 2024Filed 24mo agofiledDPC fine: Meta, plaintext passwordsDecidedData breachIrish DPCEUR 91 million
Caption and links

In the Matter of Marriott International, Inc. and Starwood Hotels & Resorts Worldwide, LLC

Lawsuit updates by email

Tuesdays, only in weeks with rulings, filings or hearings in data and AI cases.

Double opt-in. Unsubscribe any time.