Skip to Main Content
Colorado Attorney General

Phil Weiser

Colorado Attorney General

File A Complaint
  • About Us
    • Attorney General Bio & Photos
    • Vision & Values
    • Senior Staff & Organization
    • Colorado Attorney General Annual Report
    • Attorney General Opinions
    • Budget & Accounting
    • Contact Our Office
  • Sections
    • Administration
    • Civil Litigation & Employment Law
    • Consumer Protection
    • Criminal Appeals
    • Criminal Justice
    • Natural Resources & Environment
    • Division of Community Engagement
    • Revenue & Regulatory Law
    • State Services
  • Careers
    • Attorney & Other Non-Classified Positions
    • Fellowships
    • Internships
    • Classified Staff Positions
    • Other Opportunities to Join our Team
  • Media Center
    • Press Room
    • Colorado Open Records Act – CORA
  • Resources
    • Survivors of Childhood Sexual Abuse
    • Victim Assistance
    • Data Protection Laws
    • Colorado Privacy Act
    • Funding Opportunities
    • Office of Financial Empowerment
    • Code of Colorado Regulations
    • Colorado Revised Statutes
    • Transparency Online Project (TOPS)
  • Licensing
    • Business Resources
    • Collection Agencies & Debt Collectors
    • Credit Services Organizations
    • UCCC Licensing & Notification
    • Debt Management Services Providers
    • Health Club Bonds
    • Repossessors
    • Student Loan Servicer Licensing
    • Telemarketing
  • Recursos en español

Colorado to receive $822,434 from nationwide Marriott guest reservation system data breach settlement

Oct. 9, 2024 (DENVER) – Attorney General Phil Weiser announced today that a bipartisan coalition of 50 attorneys general has reached a settlement with hotel chain Marriott International, Inc. after an investigation into a large, multi-year data breach revealed the company failed to comply with consumer protection and personal information protection laws.

Under the settlement with the attorneys general, Marriott agrees to strengthen its data security practices, provide consumers with better protections, and make a $52 million payment to states. Colorado will receive $822,434 from the settlement.

“The law makes it clear to companies that they have to implement reasonable cybersecurity safeguards,” said Weiser. “By failing to comply with the law, Marriott harmed those whose data was stolen. With this settlement, we are not only holding the company accountable for their failure to protect customers and follow the law, we are also requiring them to do a better job moving forward.”

The yearslong breach of the Starwood guest reservation system, during which time intruders went undetected, stretched from July 2014 until September 2018. In 2016, Marriott acquired Starwood and took over its computer system, but did not diagnose and reveal the breach until years later.

During the breach, criminals stole 131.5 million guest records pertaining to customers in the United States. The affected records included contact information, gender, dates of birth, legacy Starwood guest information, reservation information, and hotel stay preferences, as well as a limited number of unencrypted passport numbers and unexpired payment card information.

Shortly after Marriott announced the breach of the Starwood database, nearly every attorney general in the country launched an investigation. Today’s settlement resolves allegations by Weiser and the other attorneys general that Marriott violated state consumer protection laws and personal information protection laws.

Under the terms of the settlement, Marriott has agreed to strengthen and continually improve its cybersecurity practices by implementing better training for employees, adopting better data security policies, minimizing the amount of consumer data the company collects and retains, conducting risk assessments according to best practices including assessing potential risks when acquiring new companies and products, and undergoing regular third-party security assessments for the next 20 years.

Additionally, as part of the settlement, Marriott will give consumers a data deletion option and offer multi-factor authentication to consumers for their loyalty rewards accounts, such as Marriott Bonvoy, as well as reviews of those accounts if there is suspicious activity.

The settlement money Marriott will pay to the state may be used for any restitution where possible, consumer education or consumer protection enforcement, or efforts to advance the public welfare.

# # #

Most Recent

Colorado attorney general logo against mountain peaks background and text that reads News from Attorney General Phil Weiser

Attorney General Phil Weiser statement on the states not reaching agreement on future of Colorado River

Feb. 13, 2026 (DENVER) — Attorney General Phil Weiser today issued the following statement in regarding the end of negotiations over future management of the Colorado River without an agreement: “I am disappointed that the seven Basin States could not reach a consensus agreement […]

Colorado attorney general logo against mountain peaks background and text that reads News from Attorney General Phil Weiser

Attorney General Phil Weiser statement on U.S. EPA revoking a key policy to combat climate change

Feb. 12, 2026 (DENVER) — Attorney General Phil Weiser today issued the following statement in response to the U.S. Environmental Protection Agency’s final rule rescinding the 2009 endangerment finding, which determined that greenhouse gas emissions from motor vehicles contribute to […]

Colorado attorney general logo against mountain peaks background and text that reads News from Attorney General Phil Weiser

Attorney General Phil Weiser sues Trump administration over unlawful directive to cut more than $600M in federal public health grants

Feb. 11, 2026 (DENVER) – Attorney General Phil Weiser and the attorneys general from California, Illinois and Minnesota today sued the Trump administration over the White House Office of Management and Budget’s directive to unlawfully cut more than $600 million […]

Office of the Attorney General
Colorado Department of Law
Ralph L. Carr Judicial Building
1300 Broadway, 10th Floor
Denver, CO 80203

(720) 508-6000

Contact the Office of the Attorney General

Contact

ACCESSIBILITY STATEMENT

DECLARACION DE ACCESIBILIDAD

Facebook
Twitter
LinkedIn
Instagram
YouTube
BlueSky

Attorney General Phil Weiser is working to defend Colorado communities against harmful and illegal actions from the federal government.

Learn more