Advertisement
UK markets closed
  • FTSE 100

    8,433.76
    +52.41 (+0.63%)
     
  • FTSE 250

    20,645.38
    +114.08 (+0.56%)
     
  • AIM

    789.87
    +6.17 (+0.79%)
     
  • GBP/EUR

    1.1622
    +0.0011 (+0.09%)
     
  • GBP/USD

    1.2525
    +0.0001 (+0.01%)
     
  • Bitcoin GBP

    48,297.47
    -1,697.23 (-3.39%)
     
  • CMC Crypto 200

    1,302.78
    -55.23 (-4.22%)
     
  • S&P 500

    5,222.68
    +8.60 (+0.16%)
     
  • DOW

    39,512.84
    +125.08 (+0.32%)
     
  • CRUDE OIL

    78.20
    -1.06 (-1.34%)
     
  • GOLD FUTURES

    2,366.90
    +26.60 (+1.14%)
     
  • NIKKEI 225

    38,229.11
    +155.13 (+0.41%)
     
  • HANG SENG

    18,963.68
    +425.87 (+2.30%)
     
  • DAX

    18,772.85
    +86.25 (+0.46%)
     
  • CAC 40

    8,219.14
    +31.49 (+0.38%)
     

ICO fines Marriott 18.4 million pounds for failing to secure customer data

(Reuters) - Britain's data watchdog said on Friday it has fined Marriott International 18.4 million pounds ($23.98 million) in a six-year old cyber attack on its Starwood hotels reservation system in one of the largest data breaches in history.

The hack began in 2014, before Marriott offered to buy Starwood Hotels, and affected 339 million guest records.

The Information Commissioner's Office (ICO) said that Marriott failed to put appropriate measures in place to secure customers' personal data from the attack, which was from an unknown source and remained undetected until September 2018.

The regulator added that it traced the cyber attack back to 2014, but the penalty only relates to the breach from March 25, 2018, when new rules under the General Data Protection Regulation (GDPR) came into effect.

ADVERTISEMENT

The fine is much lower than the 99.2 million pounds penalty the data watchdog had proposed to levy on the hotel operator last year.

The company is also facing a London class action by millions of former guests demanding compensation.

"Marriott does not intend to appeal the decision, but makes no admission of liability in relation to the decision or the underlying allegations," the hotel chain said.

The personal data may have included names, email addresses, phone numbers and unencrypted passport numbers among other things, the ICO said.

(Reporting by Tanishaa Nadkar in Bengaluru; Editing by Shailesh Kuber)