{"id":370,"date":"2020-11-02T14:16:49","date_gmt":"2020-11-02T14:16:49","guid":{"rendered":"https:\/\/www.tsfactory.com\/forums\/?p=370"},"modified":"2020-11-02T14:19:48","modified_gmt":"2020-11-02T14:19:48","slug":"marriott-fined-18-4-million-by-uk-watchdog-over-customer-data-breach","status":"publish","type":"post","link":"https:\/\/www.tsfactory.com\/forums\/blog\/marriott-fined-18-4-million-by-uk-watchdog-over-customer-data-breach\/","title":{"rendered":"Marriott fined \u00a318.4 million by UK watchdog over customer data breach"},"content":{"rendered":"<p>The Information Commissioner&#8217;s Office (ICO) has fined Marriott \u00a318.4 million over a 2014 data breach, heavily reducing the penalty originally planned due to COVID-19 disruption.<\/p>\n<p>The Marriot hotel group was subject to a <a href=\"https:\/\/www.zdnet.com\/article\/marriott-announces-data-breach-affecting-500-million-hotel-guests\/\" target=\"_blank\" rel=\"noopener noreferrer\">2014 data breach<\/a> impacting the Starwood resort chain, acquired by Marriott in 2015.<\/p>\n<p>At the time, threat actors were able to infiltrate Starwood systems and execute malware via a web shell, including remote access tools and credential harvesting software.<\/p>\n<p>The attackers were then able to enter databases used to store guest reservation data including names, email addresses, phone numbers, passport numbers, travel details, and loyalty program information.<\/p>\n<p>The compromise continued until 2018, and over the course of four years, information belonging to roughly 339 million guests was stolen. In total, seven million records relating to UK guests were exposed.<\/p>\n<p>The <a href=\"https:\/\/ico.org.uk\/about-the-ico\/news-and-events\/news-and-blogs\/2020\/10\/ico-fines-marriott-international-inc-184million-for-failing-to-keep-customers-personal-data-secure\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">ICO says<\/a> the company failed to meet the security standards required by GDPR due to failures to &#8220;put appropriate technical or organizational measures in place&#8221; when processing data, and as such, the company contravened data protection requirements now enforced through 2018 GDPR regulations.<\/p>\n<p>However, the watchdog acknowledged that &#8220;Marriott acted promptly to contact customers and the ICO&#8221; once the cybersecurity incident was uncovered, and &#8220;acted quickly to mitigate the risk of damage suffered by customers.&#8221;<\/p>\n<p>The hotel chain, alongside rivals such as Hilton, has been forced to slash thousands of jobs as travel plans, business trips, and holidays were canceled due to the coronavirus pandemic. After posting its first <a href=\"https:\/\/uk.reuters.com\/article\/us-marriott-intnl-results\/marriott-sees-cash-burn-slowing-as-bookings-recover-from-coronavirus-lows-idUKKCN25616W\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">quarterly loss<\/a> in close to a decade, the company said it expects a cash burn of $85 million a month in 2020.<\/p>\n<p>Due to Marriott&#8217;s current struggles and with the company&#8217;s recent security improvements in mind, the ICO has still issued a fine &#8212; but one drastically cut from its originally-proposed penalty of over \u00a399 million.<\/p>\n<p>The original notice of intent to fine, issued <a href=\"https:\/\/ico.org.uk\/about-the-ico\/news-and-events\/news-and-blogs\/2019\/07\/statement-intention-to-fine-marriott-international-inc-more-than-99-million-under-gdpr-for-data-breach\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">in July 2019<\/a>, was set to \u00a399,200,396 for GDPR violations. However, the ICO says that talks with Marriot, security improvements, and the economic damage caused by COVID-19 has led to the revised figure.<\/p>\n<p>&#8220;Millions of people&#8217;s data was affected by Marriott&#8217;s failure; thousands contacted a helpline and others may have had to take action to protect their personal data because the company they trusted it with had not,&#8221; commented Elizabeth Denham, UK Information Commissioner. &#8220;When a business fails to look after customers&#8217; data, the impact is not just a possible fine, what matters most is the public whose data they had a duty to protect.&#8221;<\/p>\n<p>Last month, British Airways <a href=\"https:\/\/www.zdnet.com\/article\/data-watchdog-issues-biggest-ever-fine-over-airline-cyberattack\/\" target=\"_blank\" rel=\"noopener noreferrer\">was fined \u00a320 million<\/a> by the ICO after cyberattackers stole information belonging to over 400,000 customers in 2018.<\/p>\n<p>Source: ZDNet<\/p>\n<p><a href=\"https:\/\/www.zdnet.com\/article\/marriott-fined-gbp18-4-million-by-uk-watchdog-over-customer-data-breach\/\">Read the Full Story Here<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Information Commissioner&#8217;s Office (ICO) has fined Marriott \u00a318.4 million over a 2014 data breach, heavily reducing the penalty originally planned due to COVID-19 disruption. The Marriot hotel group was subject to a 2014 data breach impacting the Starwood resort chain, acquired by Marriott in 2015. At the time, threat actors were able to infiltrate [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":352,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-370","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Marriott fined \u00a318.4 million by UK watchdog over customer data breach - Community<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.tsfactory.com\/forums\/blog\/marriott-fined-18-4-million-by-uk-watchdog-over-customer-data-breach\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Marriott fined \u00a318.4 million by UK watchdog over customer data breach - Community\" \/>\n<meta property=\"og:description\" content=\"The Information Commissioner&#8217;s Office (ICO) has fined Marriott \u00a318.4 million over a 2014 data breach, heavily reducing the penalty originally planned due to COVID-19 disruption. The Marriot hotel group was subject to a 2014 data breach impacting the Starwood resort chain, acquired by Marriott in 2015. At the time, threat actors were able to infiltrate [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.tsfactory.com\/forums\/blog\/marriott-fined-18-4-million-by-uk-watchdog-over-customer-data-breach\/\" \/>\n<meta property=\"og:site_name\" content=\"Community\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/TSFactoryLLC\/\" \/>\n<meta property=\"article:published_time\" content=\"2020-11-02T14:16:49+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-11-02T14:19:48+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.tsfactory.com\/forums\/wp-content\/uploads\/2020\/10\/pexels-josh-sorenson-1714208.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"853\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Chelsie Wyatt\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@TSFactoryLLC\" \/>\n<meta name=\"twitter:site\" content=\"@TSFactoryLLC\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Chelsie Wyatt\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.tsfactory.com\/forums\/blog\/marriott-fined-18-4-million-by-uk-watchdog-over-customer-data-breach\/\",\"url\":\"https:\/\/www.tsfactory.com\/forums\/blog\/marriott-fined-18-4-million-by-uk-watchdog-over-customer-data-breach\/\",\"name\":\"Marriott fined \u00a318.4 million by UK watchdog over customer data breach - Community\",\"isPartOf\":{\"@id\":\"https:\/\/www.tsfactory.com\/forums\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.tsfactory.com\/forums\/blog\/marriott-fined-18-4-million-by-uk-watchdog-over-customer-data-breach\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.tsfactory.com\/forums\/blog\/marriott-fined-18-4-million-by-uk-watchdog-over-customer-data-breach\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.tsfactory.com\/forums\/wp-content\/uploads\/2020\/10\/pexels-josh-sorenson-1714208.jpg\",\"datePublished\":\"2020-11-02T14:16:49+00:00\",\"dateModified\":\"2020-11-02T14:19:48+00:00\",\"author\":{\"@id\":\"https:\/\/www.tsfactory.com\/forums\/#\/schema\/person\/9d9908f0e12559297335ebe9b601c82f\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.tsfactory.com\/forums\/blog\/marriott-fined-18-4-million-by-uk-watchdog-over-customer-data-breach\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.tsfactory.com\/forums\/blog\/marriott-fined-18-4-million-by-uk-watchdog-over-customer-data-breach\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.tsfactory.com\/forums\/blog\/marriott-fined-18-4-million-by-uk-watchdog-over-customer-data-breach\/#primaryimage\",\"url\":\"https:\/\/www.tsfactory.com\/forums\/wp-content\/uploads\/2020\/10\/pexels-josh-sorenson-1714208.jpg\",\"contentUrl\":\"https:\/\/www.tsfactory.com\/forums\/wp-content\/uploads\/2020\/10\/pexels-josh-sorenson-1714208.jpg\",\"width\":1280,\"height\":853},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.tsfactory.com\/forums\/blog\/marriott-fined-18-4-million-by-uk-watchdog-over-customer-data-breach\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.tsfactory.com\/forums\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Marriott fined \u00a318.4 million by UK watchdog over customer data breach\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.tsfactory.com\/forums\/#website\",\"url\":\"https:\/\/www.tsfactory.com\/forums\/\",\"name\":\"Community\",\"description\":\"TSFactory\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.tsfactory.com\/forums\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.tsfactory.com\/forums\/#\/schema\/person\/9d9908f0e12559297335ebe9b601c82f\",\"name\":\"Chelsie Wyatt\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.tsfactory.com\/forums\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/09ff3801fb7566acf715fe4e81a9bd942b923c236138a3ed8a8375f099e5d6d6?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/09ff3801fb7566acf715fe4e81a9bd942b923c236138a3ed8a8375f099e5d6d6?s=96&d=mm&r=g\",\"caption\":\"Chelsie Wyatt\"},\"url\":\"https:\/\/www.tsfactory.com\/forums\/blog\/author\/chelsie\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Marriott fined \u00a318.4 million by UK watchdog over customer data breach - Community","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.tsfactory.com\/forums\/blog\/marriott-fined-18-4-million-by-uk-watchdog-over-customer-data-breach\/","og_locale":"en_US","og_type":"article","og_title":"Marriott fined \u00a318.4 million by UK watchdog over customer data breach - Community","og_description":"The Information Commissioner&#8217;s Office (ICO) has fined Marriott \u00a318.4 million over a 2014 data breach, heavily reducing the penalty originally planned due to COVID-19 disruption. The Marriot hotel group was subject to a 2014 data breach impacting the Starwood resort chain, acquired by Marriott in 2015. At the time, threat actors were able to infiltrate [&hellip;]","og_url":"https:\/\/www.tsfactory.com\/forums\/blog\/marriott-fined-18-4-million-by-uk-watchdog-over-customer-data-breach\/","og_site_name":"Community","article_publisher":"https:\/\/www.facebook.com\/TSFactoryLLC\/","article_published_time":"2020-11-02T14:16:49+00:00","article_modified_time":"2020-11-02T14:19:48+00:00","og_image":[{"width":1280,"height":853,"url":"https:\/\/www.tsfactory.com\/forums\/wp-content\/uploads\/2020\/10\/pexels-josh-sorenson-1714208.jpg","type":"image\/jpeg"}],"author":"Chelsie Wyatt","twitter_card":"summary_large_image","twitter_creator":"@TSFactoryLLC","twitter_site":"@TSFactoryLLC","twitter_misc":{"Written by":"Chelsie Wyatt","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.tsfactory.com\/forums\/blog\/marriott-fined-18-4-million-by-uk-watchdog-over-customer-data-breach\/","url":"https:\/\/www.tsfactory.com\/forums\/blog\/marriott-fined-18-4-million-by-uk-watchdog-over-customer-data-breach\/","name":"Marriott fined \u00a318.4 million by UK watchdog over customer data breach - Community","isPartOf":{"@id":"https:\/\/www.tsfactory.com\/forums\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.tsfactory.com\/forums\/blog\/marriott-fined-18-4-million-by-uk-watchdog-over-customer-data-breach\/#primaryimage"},"image":{"@id":"https:\/\/www.tsfactory.com\/forums\/blog\/marriott-fined-18-4-million-by-uk-watchdog-over-customer-data-breach\/#primaryimage"},"thumbnailUrl":"https:\/\/www.tsfactory.com\/forums\/wp-content\/uploads\/2020\/10\/pexels-josh-sorenson-1714208.jpg","datePublished":"2020-11-02T14:16:49+00:00","dateModified":"2020-11-02T14:19:48+00:00","author":{"@id":"https:\/\/www.tsfactory.com\/forums\/#\/schema\/person\/9d9908f0e12559297335ebe9b601c82f"},"breadcrumb":{"@id":"https:\/\/www.tsfactory.com\/forums\/blog\/marriott-fined-18-4-million-by-uk-watchdog-over-customer-data-breach\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.tsfactory.com\/forums\/blog\/marriott-fined-18-4-million-by-uk-watchdog-over-customer-data-breach\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.tsfactory.com\/forums\/blog\/marriott-fined-18-4-million-by-uk-watchdog-over-customer-data-breach\/#primaryimage","url":"https:\/\/www.tsfactory.com\/forums\/wp-content\/uploads\/2020\/10\/pexels-josh-sorenson-1714208.jpg","contentUrl":"https:\/\/www.tsfactory.com\/forums\/wp-content\/uploads\/2020\/10\/pexels-josh-sorenson-1714208.jpg","width":1280,"height":853},{"@type":"BreadcrumbList","@id":"https:\/\/www.tsfactory.com\/forums\/blog\/marriott-fined-18-4-million-by-uk-watchdog-over-customer-data-breach\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.tsfactory.com\/forums\/"},{"@type":"ListItem","position":2,"name":"Marriott fined \u00a318.4 million by UK watchdog over customer data breach"}]},{"@type":"WebSite","@id":"https:\/\/www.tsfactory.com\/forums\/#website","url":"https:\/\/www.tsfactory.com\/forums\/","name":"Community","description":"TSFactory","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.tsfactory.com\/forums\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.tsfactory.com\/forums\/#\/schema\/person\/9d9908f0e12559297335ebe9b601c82f","name":"Chelsie Wyatt","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.tsfactory.com\/forums\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/09ff3801fb7566acf715fe4e81a9bd942b923c236138a3ed8a8375f099e5d6d6?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/09ff3801fb7566acf715fe4e81a9bd942b923c236138a3ed8a8375f099e5d6d6?s=96&d=mm&r=g","caption":"Chelsie Wyatt"},"url":"https:\/\/www.tsfactory.com\/forums\/blog\/author\/chelsie\/"}]}},"_links":{"self":[{"href":"https:\/\/www.tsfactory.com\/forums\/wp-json\/wp\/v2\/posts\/370","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.tsfactory.com\/forums\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.tsfactory.com\/forums\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.tsfactory.com\/forums\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.tsfactory.com\/forums\/wp-json\/wp\/v2\/comments?post=370"}],"version-history":[{"count":2,"href":"https:\/\/www.tsfactory.com\/forums\/wp-json\/wp\/v2\/posts\/370\/revisions"}],"predecessor-version":[{"id":372,"href":"https:\/\/www.tsfactory.com\/forums\/wp-json\/wp\/v2\/posts\/370\/revisions\/372"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.tsfactory.com\/forums\/wp-json\/wp\/v2\/media\/352"}],"wp:attachment":[{"href":"https:\/\/www.tsfactory.com\/forums\/wp-json\/wp\/v2\/media?parent=370"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.tsfactory.com\/forums\/wp-json\/wp\/v2\/categories?post=370"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.tsfactory.com\/forums\/wp-json\/wp\/v2\/tags?post=370"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}