Wyndham Hotels and Resorts LLC agreed to a consent order following findings that it had failed to implement reasonable and appropriate data security for its customers' payment card information — failures that contributed to three separate data breaches occurring within a two-year period, each of which exposed hundreds of thousands of payment card accounts to fraudulent use, while Wyndham's privacy policy represented to customers that the company maintained "reasonable safeguards" to protect their personal information.DOCUMENTED
The Wyndham case was significant for regulatory enforcement in multiple respects: it established that the FTC's Section 5 authority over unfair practices extends to data security failures when those failures cause consumer harm, it was the first major contested data security case in which a company challenged the FTC's authority rather than settling immediately, and the court's ruling upholding the FTC's authority signaled that companies cannot rely on the absence of specific data security regulations to insulate their practices from consumer protection enforcement.REVIEWED
- Three separate data breaches occurred at Wyndham properties between 2008 and 2010, each compromising customer payment card accounts
- The breaches collectively exposed approximately 619,000 payment card accounts to fraudulent charges estimated at more than $10.6 million
- Security vulnerabilities exploited in the breaches included weak password practices, outdated software without security patches, and inadequate network segmentation
- The same types of vulnerabilities that allowed the first breach recurred in subsequent breaches, showing that remediation was inadequate after the initial incident
- Wyndham's privacy policy represented that the company used "reasonable safeguards" to protect customer information — a representation regulators found was inaccurate given the actual security practices
The Three Breaches
The three Wyndham breaches were distinct incidents but shared common underlying causes. In each case, attackers were able to access Wyndham's network by compromising the systems of individual franchise properties — which were connected to Wyndham's central data systems — and then move laterally through the network to access payment card data stored at multiple locations. The attack path worked because Wyndham's network was not adequately segmented: a compromise of one property's system provided access to data across the larger network rather than being contained to that property's systems.DOCUMENTED
Each breach exploited vulnerabilities that were either known at the time of the attack, had been identified in prior breaches that were not fully remediated, or were consistent with security practices that the industry had recognized as inadequate. Default or easily guessed passwords were used on systems that should have required strong authentication. Outdated software without current security patches remained in production use. Network monitoring that might have detected the lateral movement of attackers was not implemented or was not functioning effectively. These are not sophisticated failure modes — they are the elementary security practices whose absence makes breaches preventable.DOCUMENTED
The Recurrence Problem
The most significant data security finding from a regulatory perspective was that the same categories of vulnerability that allowed the first breach recurred in the second and third breaches. When a company suffers a data breach, investigates its causes, and purports to remediate the identified vulnerabilities, the recurrence of similar vulnerabilities in subsequent incidents is evidence that the remediation was inadequate or that the company's security program did not systematically address the underlying causes rather than just the specific technical configurations exploited in a single incident.DOCUMENTED
Wyndham's franchised hotel model — in which independently owned properties operate under the Wyndham brand and connect to Wyndham's central data systems — created specific security challenges: ensuring that franchise properties implemented and maintained adequate security practices was an organizational responsibility that Wyndham had not fulfilled through either contractual requirements, technical controls, or oversight processes adequate to maintain the security of the larger network. A central reservation and data system that aggregates data from many independently operated properties is only as secure as its least secure connection point if network segmentation is inadequate.REVIEWED
Wyndham's second and third breaches exploited vulnerabilities similar to those identified in the first — demonstrating that its post-breach remediation had not addressed the systemic security failures that made the initial compromise possible, and that those same conditions persisted throughout the breach period.
The Unfair Practice Theory
Wyndham challenged the FTC's authority to bring a data security enforcement action as an unfair practice, arguing that the FTC had not specified what data security practices it considered required and that companies should not face liability without advance notice of the applicable standard. The court that reviewed Wyndham's challenge rejected this argument, finding that the FTC's unfairness authority applies to data security failures that cause substantial consumer harm and that the FTC is not required to issue a specific regulation before bringing an enforcement action for failures that fall below the objective standard of reasonable security practices.REVIEWED
The ruling's implications for data security enforcement have been significant: companies that experience data breaches cannot rely on the absence of specific security regulations to avoid FTC enforcement, and the focus of inquiry is whether the security practices that were in place were reasonable and appropriate given the sensitivity of the data held and the foreseeable threats to that data. For hospitality companies and any other organization that processes large volumes of payment card data on behalf of customers who reasonably expect their payment information to be secure, reasonable security practices are a legal obligation under this framework regardless of whether specific technical standards have been incorporated into a formal regulation.DOCUMENTED
Protecting Your Payment Data When Traveling
Hotel stays typically require providing payment card information that is stored in the hotel's reservation system and used for incidental charges during the stay. Several practices can reduce the risk of payment data exposure from hotel data breaches. Using a virtual card number — offered by many credit card issuers through their mobile apps — provides a temporary card number specific to the hotel transaction that cannot be used by an attacker who compromises the hotel's system, because the virtual number is typically limited to the merchant it was created for and expires after the transaction. Paying for hotel stays with a credit card rather than a debit card provides better dispute rights if the card number is used fraudulently — credit card fraud disputes do not affect your bank account balance while being investigated, while debit card fraud disputes may involve a temporary loss of funds during the investigation period. Monitoring your card statements for unfamiliar charges after any hotel stay and reporting suspicious charges promptly to your card issuer starts the dispute clock and preserves your chargeback rights. The hotel data breach environment remains active — maintaining alert habits after travel transactions is a practical protection regardless of which hotel chain you stay at.
Sources behind this report
Have documents relevant to this story? Reach us through our tips channel.