Skip to Main Content
Colorado Attorney General

Phil Weiser

Colorado Attorney General

File A Complaint
  • About Us
    • Attorney General Bio & Photos
    • Vision & Values
    • Senior Staff & Organization
    • Colorado Attorney General Annual Report
    • Attorney General Opinions
    • Budget & Accounting
    • Contact Our Office
  • Sections
    • Administration
    • Civil Litigation & Employment Law
    • Consumer Protection
    • Criminal Appeals
    • Criminal Justice
    • Natural Resources & Environment
    • Division of Community Engagement
    • Revenue & Regulatory Law
    • State Services
  • Careers
    • Attorney & Other Non-Classified Positions
    • Fellowships
    • Internships
    • Classified Staff Positions
    • Other Opportunities to Join our Team
  • Media Center
    • Press Room
    • Colorado Open Records Act – CORA
  • Resources
    • Survivors of Childhood Sexual Abuse
    • Victim Assistance
    • Colorado Privacy Act
    • Data Protection Laws
    • Extreme Risk Protection Order (ERPO) Trainings and Resources
    • Funding Opportunities
    • Office of Financial Empowerment
    • Code of Colorado Regulations
    • Colorado Revised Statutes
    • Transparency Online Project (TOPS)
  • Licensing
    • Business Resources
    • Collection Agencies & Debt Collectors
    • Credit Services Organizations
    • UCCC Licensing & Notification
    • Debt Management Services Providers
    • Health Club Bonds
    • Repossessors
    • Student Loan Servicer Licensing
    • Telemarketing
  • Recursos en español

Colorado to receive $822,434 from nationwide Marriott guest reservation system data breach settlement

Oct. 9, 2024 (DENVER) – Attorney General Phil Weiser announced today that a bipartisan coalition of 50 attorneys general has reached a settlement with hotel chain Marriott International, Inc. after an investigation into a large, multi-year data breach revealed the company failed to comply with consumer protection and personal information protection laws.

Under the settlement with the attorneys general, Marriott agrees to strengthen its data security practices, provide consumers with better protections, and make a $52 million payment to states. Colorado will receive $822,434 from the settlement.

“The law makes it clear to companies that they have to implement reasonable cybersecurity safeguards,” said Weiser. “By failing to comply with the law, Marriott harmed those whose data was stolen. With this settlement, we are not only holding the company accountable for their failure to protect customers and follow the law, we are also requiring them to do a better job moving forward.”

The yearslong breach of the Starwood guest reservation system, during which time intruders went undetected, stretched from July 2014 until September 2018. In 2016, Marriott acquired Starwood and took over its computer system, but did not diagnose and reveal the breach until years later.

During the breach, criminals stole 131.5 million guest records pertaining to customers in the United States. The affected records included contact information, gender, dates of birth, legacy Starwood guest information, reservation information, and hotel stay preferences, as well as a limited number of unencrypted passport numbers and unexpired payment card information.

Shortly after Marriott announced the breach of the Starwood database, nearly every attorney general in the country launched an investigation. Today’s settlement resolves allegations by Weiser and the other attorneys general that Marriott violated state consumer protection laws and personal information protection laws.

Under the terms of the settlement, Marriott has agreed to strengthen and continually improve its cybersecurity practices by implementing better training for employees, adopting better data security policies, minimizing the amount of consumer data the company collects and retains, conducting risk assessments according to best practices including assessing potential risks when acquiring new companies and products, and undergoing regular third-party security assessments for the next 20 years.

Additionally, as part of the settlement, Marriott will give consumers a data deletion option and offer multi-factor authentication to consumers for their loyalty rewards accounts, such as Marriott Bonvoy, as well as reviews of those accounts if there is suspicious activity.

The settlement money Marriott will pay to the state may be used for any restitution where possible, consumer education or consumer protection enforcement, or efforts to advance the public welfare.

# # #

Most Recent

Colorado attorney general logo against mountain peaks background and text that reads News from Attorney General Phil Weiser

Attorney General Phil Weiser sues U.S. Department of Education over restrictions on student loan access for healthcare professionals

May 19, 2026 (DENVER) — Attorney General Phil Weiser today co-led a coalition of 24 attorneys general and two governors in suing the U.S. Department of Education over a new final rule that would significantly limit federal student loan access for […]

Colorado attorney general logo against mountain peaks background and text that reads News from Attorney General Phil Weiser

Attorney General Phil Weiser statement on Colorado Supreme Court directing Children's Hospital to resume gender-affirming care

May 18, 2026 (DENVER) — Attorney General Phil Weiser released the following statement regarding the opinion from the Colorado Supreme Court in Boe v. Children’s Hospital Colorado: “With today’s Colorado Supreme Court decision, Colorado families are finally going to get […]

Colorado attorney general logo against mountain peaks background and text that reads News from Attorney General Phil Weiser

Attorney General Phil Weiser: Commuting Tina Peters' prison sentence 'mind-boggling and wrong'

May 15, 2026 (DENVER) — Attorney General Phil Weiser released the following statement regarding the governor commuting the sentence of convicted former Mesa County clerk Tina Peters: “Gov. Polis’ commutation of Tina Peters’ sentence is mind-boggling and wrong as a matter […]

Office of the Attorney General
Colorado Department of Law
Ralph L. Carr Judicial Building
1300 Broadway, 10th Floor
Denver, CO 80203

(720) 508-6000

Contact the Office of the Attorney General

Contact

ACCESSIBILITY STATEMENT

DECLARACION DE ACCESIBILIDAD

Facebook
Twitter
LinkedIn
Instagram
YouTube
BlueSky

Attorney General Phil Weiser is working to defend Colorado communities against harmful and illegal actions from the federal government.

Learn more: Defending Colorado