Iowa to receive over $500K in nationwide settlement after Marriott data breach
Summary
Attorney General Brenna Bird announced Iowa has joined every other state and the District of Columbia in a $52 million settlement with Marriott International for a data breach that exposed guest information. “This settlement holds Marriott accountable for exposing more than 131 million guest records, containing Americans’ data, and requires safeguards to ensure all future guests are protected.” The breach happened after Marriott acquired Starwood Hotels and Resorts Worldwide, LLC in 2016 and was not detected until 2018. However, according to the settlement, forensic examiners determined Starwoods network was compromised in 2014 before Marriott acquired the company. Key loggers, memory-scraping malware and Remote Access Trojans were used in over 480 systems across 58 Starwood locations, according to the settlement. As part of the settlement, Marriott has agreed to strengthen its cybersecurity practices including the implementation of an information security program, reduction of collected and contained guest data, more network safeguards and more IT oversight.