The Federal Trade Commission has mandated that Marriott and Starwood implement a robust information security program, following significant breaches exposing 344 million customers' data.
Marriott and Starwood's security failures, including inadequate password controls and lack of multifactor authentication, led to multiple data breaches affecting hundreds of millions.
Under the settlement, both companies must provide U.S. customers a method to delete personal information linked to their loyalty accounts or email addresses.
The FTC proposed that Marriott’s deceptive practices misled consumers who believed they had sufficient data security, while reality revealed significant vulnerabilities.
Collection
[
|
...
]