Marriott is the victim of "cyber" crimes.
Marriott's customers are victims of Marriott's negligence.
I'd argue it has nothing to do with corporation or non-corporation. If someone is injured in a car accident due to an unfastened seatbelt, the driver is also potentially both a victim (assuming they weren't at fault for the accident) and guilty of negligence (for not making sure safety equipment was used properly).
Marriott was literally, prima facie, the victim of a hacker. The data didn't steal itself. Someone trespassed into Marriott's network and stole data that did not belong to them.
Legal culpability, while certainly not the strong point of HN, is a thing. Negligent, grossly negligent, and reckless conduct are technical terms that exist and have meaning.
I'm sick of replying to this because I don't like defending Marriott in this case. I hope they get a painful class action ruling. I think legal reforms around this are needed, but I am entirely unconvinced anyone here has a reasonable framework of regulations that would benefit anyone.
I agree with that criticism. It's not a crime to be a victim, but being a victim also doesn't mean you're not guilty.
Marriott might, however, still be liable for some damages due to not following common security practices for sensitive personal information. Anyone from California, for example, would have § 1798.81.5 [1] and § 1798.91.04 [2] which would backup their right to have their data handled properly. The FTC might also get involved with their fairly broad powers to protect users privacy (though that agency has been limited in this administration).
[1] http://leginfo.legislature.ca.gov/faces/codes_displaySection... [2] https://leginfo.legislature.ca.gov/faces/billCompareClient.x...
> " benefits from the crime."
These corporations are benefiting from their negligence every day when they save money by being negligent with security and facing no real consequences for it.
A huge corporation will mostly see a fine as a cost of doing business. It won't work when you're looking at negligence, or security, because you can hedge all of your bets on never being found out, or otherwise only being found out so far in the future that the negligence has already paid for itself.
Regulating the storage of sensitive information, same as you have with HIPAA and GDPR, presents a much stronger case for being more careful up front. You're no longer talking about negligence: the expectation for how you handle sensitive info is made clear right from the start, and you can treat egregious violations (like storing passport numbers alongside other account details like a physical address without securing the system) as malicious.
Think of what would happen if we punished the hell out of Marriot. Many of those people could lose their jobs and be unable to provide for their families, for something that didn’t really have much to do with them other than they chose to work at the wrong corporation.