FTC sues Wyndham Hotels for data security failures.

PositionDATA SECURITY

Over the course of two years, hotel operator Wyndham Worldwide experienced three network data breaches, which ultimately led to $10.6 million in fraudulent credit card charges on consumers' accounts and the export of 600,000 account records to a domain registered in Russia.

Three occurrences in two years was a clear indication to the U.S. Federal Trade Commission (FTC) that Wyndham Worldwide and three of its subsidiaries had failed to employ appropriate information security practices. In June, the FTC filed a lawsuit against Wyndham alleging the hotel chain failed to "maintain reasonable and appropriate data security for consumers' sensitive personal information."

In the filing, the FTC's allegations included that Wyndham:

* Failed to use readily available security measures to limit access to the network

* Allowed software at the hotels to be configured so as to store payment card information unencrypted

* Failed to ensure all hotels implemented adequate information security policies and procedures

* Failed to remedy known security vulnerabilities on network servers

* Failed to employ adequate password requirements and...

To continue reading

Request your trial

VLEX uses login cookies to provide you with a better browsing experience. If you click on 'Accept' or continue browsing this site we consider that you accept our cookie policy. ACCEPT