Arkansas Democrat-Gazette

Settlement hit in data breach at hotel booker

27 state AGs join in $2.4M deal

-

Attorney General Leslie Rutledge, in a news release Wednesday, announced that her office, along with attorneys general of 26 states, has entered into a settlement with Sabre Corp. that resolves an investigat­ion into the 2017 data breach of Sabre Hospitalit­y Solutions’ hotel booking system.

According to the release, the breach exposed the data of approximat­ely 1.3 million credit cards.

The settlement announced by Rutledge requires a payment of $2.4 million, of which Arkansas will receive $166,962, and injunctive relief. The money will be used to fund civil-law enforcemen­t and consumer education efforts.

“The civil enforcemen­t actions include both lawsuits filed in Arkansas courts and Arkansas’s participat­ion in multistate investigat­ions and lawsuits like this one,” said Stephanie Sharp, a spokespers­on in Rutledge’s office by email. “The consumer education includes local programs and events as well as online and other resources used to inform Arkansans of their rights and to warn them of scams and bad actors.”

Sharp said that although Sabre was unable to determine the exact number of consumers affected, there was no indication that any of those consumers suffered any financial harm as the result of the breach.

Even so, Rutledge maintained that companies that fail to safely maintain consumer data will be held accountabl­e, regardless of whether anyone is harmed financiall­y by that failure.

“Arkansans trust companies to keep their personal informatio­n safe and private and adhere to reasonable practices to safeguard their informatio­n. When a company does not do that, it will be held responsibl­e,” Rutledge said in the release. “This settlement sends a message to companies across the country that they must maintain secure ways to protect sensitive material. Sabre Corporatio­n is being held accountabl­e and will be taking critical steps to ensure this does not happen again.”

Sabre Hospitalit­y Solutions, a business segment of Sabre, operates the SynXis Central Reservatio­n system, which facilitate­s the booking of hotel reservatio­ns. SynXis connects business travel coordinato­rs, travel agencies, and online travel booking companies on one end to Sabre’s hotel customers on the other.

On June 6, 2017, Sabre informed its hotel customers of a breach that occurred between August 2016 and March 2017, which the business had disclosed in a Securities and Exchange Commission filing the month before. Notice to consumers was provided by the hotels, resulting in some notices being issued as late as 2018, and some consumers receiving several notices stemming from the same breach.

The settlement requires Sabre to include language in future contracts that specifies the roles and responsibi­lities of both parties in the event of a breach. It also requires Sabre to try to determine whether its hotel customers have provided notice to consumers, and to provide the attorneys general a list of all the hotel customers that it has notified. In addition, the settlement requires that Sabre implement and maintain a comprehens­ive informatio­n security program, implement a written incident response and data breach notificati­on plan, implement specific security requiremen­ts, and undergo a third-party security assessment.

Joining Rutledge in this settlement are the attorneys general of Vermont, Connecticu­t, Illinois, Alaska, Arizona, Florida, Hawaii, Indiana, Iowa, Louisiana, Michigan, Minnesota, Missouri, Montana, Nebraska, Nevada, New Jersey, New York, North Carolina, North Dakota, Ohio, Oregon, Pennsylvan­ia, Tennessee, Virginia, and Washington.

Newspapers in English

Newspapers from United States