NY AG Announces Probe of Marriott Data Breach and Its Failure to Report Incident
A spokeswoman for Underwood's office confirmed Friday morning that they were looking into the breach and that the company may have violated state law by not notifying the attorney general of the incident.
November 30, 2018 at 11:34 AM
5 minute read
New York Attorney General Barbara Underwood is investigating a data breach that compromised the data of approximately 500 million persons who made reservations at Marriott International's Starwood hotels.
A spokeswoman for Underwood's office confirmed Friday morning that they were looking into the breach and that the company may have violated state law by not notifying the attorney general of the incident.
“We've opened an investigation into the Marriott data breach,” said Amy Spitalnick, spokeswoman for Underwood. “Additionally, under New York law, Marriott was required to provide notification to our office upon discovering the breach; they have not done so as of yet.”
Marriott, which announced the data breach early Friday morning, said in a statement that they are working on filing regulatory notices with state authorities following their announcement of the breach.
“We are in the process of completing the filing of all regulatory notices this morning,” a spokesman for Marriott said.
Underwood was among the first state attorneys general to confirm an investigation into the breach Friday morning. The reach of her investigation, and any civil litigation arising from it, would be limited to the breach's impact on New York residents. The attorney general's office typically, in situations like these, partners with attorneys general from several states to reach a national settlement for victims of an incident.
The multinational hotel chain is headquartered outside New York in Bethesda, Maryland. Maryland Attorney General Brian Frosh said in a statement Friday morning that his office would be taking a “hard look” at the security incident, though a spokeswoman said they typically do not confirm nor deny active investigations into a company.
“The Marriott data breach is one of the largest and most alarming we've seen,” Frosh said. “My office will be taking a hard look at Marriott's actions to understand the circumstances that led to the breach.”
Frosh also said his office will be working with the company to make sure users affected by the breach are notified. They will also be monitoring the company's response to the incident, Frosh said.
Marriott announced Friday morning that an investigation that ended nearly two weeks ago had confirmed the data breach. The company launched the investigation after it was informed of a possible security incident by an internal security tool on Sept. 8, according to Marriott. The investigation determined that there had been unauthorized access to the Starwood network since 2014.
The incident compromised the data of 500 million people who made a reservation at one of the company's Starwood properties on or before Sept. 10, Marriott said. For an unknown number of those customers, the information obtained may have included credit card numbers and their expiration dates. Those were encrypted in the system, Marriott said, but whoever accessed the database may have been able to decrypt them.
About two-thirds of users had other information compromised as well, including their passport number, name, mailing address, phone number, email address, date of birth and gender. The breach also compromised details on their stay at the Starwood property, as well as their account information with the Starwood Preferred Guest program.
The company said it's already reported the incident to law enforcement and has begun notifying regulatory authorities. As of Friday morning, authorities in New York had not been notified, Spitalnick said.
New York state law requires that a company inform the state's affected residents when a person acquires their personal computerized data without valid authorization. There are situations, according to the law, where a company may be asked to delay notifying its users if that message would impede a criminal investigation.
When it's discovered, a security breach has to be reported by a company to three state entities: the attorney general's office, the state police and the Department of State. The Consumer Frauds and Protection Bureau within the attorney general's office handles incidents involving a security breach. Marriott had failed to inform any of the three as of Friday morning, according to the attorney general's office.
The data breach affected customers who stayed at more than a half-dozen of the company's Starwood properties, including W Hotels, St. Regis, Sheraton Hotels & Resorts, Westin Hotels & Resorts, Element Hotels, Aloft Hotels, The Luxury Collection, Tribute Portfolio, Le Méridien Hotels & Resorts, Four Points by Sheraton and Design Hotels. Starwood-branded timeshare properties also were impacted.
“We deeply regret this incident happened,” said Arne Sorenson, Marriott's president and CEO. “We fell short of what our guests deserve and what we expect of ourselves. We are doing everything we can to support our guests, and using lessons learned to be better moving forward.”
The company has created a website to address the concerns of users who suspect they may have been affected. That can be found at info.starwoodhotels.com. Customers also may call the company's call center for the breach, which is at 877-273-9481 for users in the U.S. Marriott also will begin sending emails to affected users on a rolling basis, starting Friday.
READ MORE:
Federal Data Privacy Legislation Is Likely Next Year, Tech Lawyers Say
Equifax Agrees to New Data Breach Safeguards in Consent Order With State Regulators
New DFS Cybersecurity Regulations Are Here: Will Your Insurance Protect You?
Online Lenders Should Be Subject to State Regulations, DFS Says
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2025 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View AllProsecutors Ask Judge to Question Charlie Javice Lawyer Over Alleged Conflict
Trending Stories
- 1'Astronomical' Interest Rates: $1B Settlement to Resolve Allegations of 'Predatory' Lending Cancels $534M in Small-Business Debts
- 2Senator Plans to Reintroduce Bill to Split 9th Circuit
- 3Law Firms Converge to Defend HIPAA Regulation
- 4Judge Denies Retrial Bid by Ex-U.S. Sen. Menendez Over Evidentiary Error
- 5Lawyers: Meet Your New Partner
Who Got The Work
J. Brugh Lower of Gibbons has entered an appearance for industrial equipment supplier Devco Corporation in a pending trademark infringement lawsuit. The suit, accusing the defendant of selling knock-off Graco products, was filed Dec. 18 in New Jersey District Court by Rivkin Radler on behalf of Graco Inc. and Graco Minnesota. The case, assigned to U.S. District Judge Zahid N. Quraishi, is 3:24-cv-11294, Graco Inc. et al v. Devco Corporation.
Who Got The Work
Rebecca Maller-Stein and Kent A. Yalowitz of Arnold & Porter Kaye Scholer have entered their appearances for Hanaco Venture Capital and its executives, Lior Prosor and David Frankel, in a pending securities lawsuit. The action, filed on Dec. 24 in New York Southern District Court by Zell, Aron & Co. on behalf of Goldeneye Advisors, accuses the defendants of negligently and fraudulently managing the plaintiff's $1 million investment. The case, assigned to U.S. District Judge Vernon S. Broderick, is 1:24-cv-09918, Goldeneye Advisors, LLC v. Hanaco Venture Capital, Ltd. et al.
Who Got The Work
Attorneys from A&O Shearman has stepped in as defense counsel for Toronto-Dominion Bank and other defendants in a pending securities class action. The suit, filed Dec. 11 in New York Southern District Court by Bleichmar Fonti & Auld, accuses the defendants of concealing the bank's 'pervasive' deficiencies in regards to its compliance with the Bank Secrecy Act and the quality of its anti-money laundering controls. The case, assigned to U.S. District Judge Arun Subramanian, is 1:24-cv-09445, Gonzalez v. The Toronto-Dominion Bank et al.
Who Got The Work
Crown Castle International, a Pennsylvania company providing shared communications infrastructure, has turned to Luke D. Wolf of Gordon Rees Scully Mansukhani to fend off a pending breach-of-contract lawsuit. The court action, filed Nov. 25 in Michigan Eastern District Court by Hooper Hathaway PC on behalf of The Town Residences LLC, accuses Crown Castle of failing to transfer approximately $30,000 in utility payments from T-Mobile in breach of a roof-top lease and assignment agreement. The case, assigned to U.S. District Judge Susan K. Declercq, is 2:24-cv-13131, The Town Residences LLC v. T-Mobile US, Inc. et al.
Who Got The Work
Wilfred P. Coronato and Daniel M. Schwartz of McCarter & English have stepped in as defense counsel to Electrolux Home Products Inc. in a pending product liability lawsuit. The court action, filed Nov. 26 in New York Eastern District Court by Poulos Lopiccolo PC and Nagel Rice LLP on behalf of David Stern, alleges that the defendant's refrigerators’ drawers and shelving repeatedly break and fall apart within months after purchase. The case, assigned to U.S. District Judge Joan M. Azrack, is 2:24-cv-08204, Stern v. Electrolux Home Products, Inc.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250