HackingStolen CredentialsData ExfiltratedSupply Chain (3P Vendor)FINANCIAL_ACCOUNTPIILowContained
Pacific Hospitality Group
bd_00ff548071ed5da2 · schema v1 · pii pii-v1
Full breach record for Pacific Hospitality Group →Pacific Hospitality Group notified California AG that Sabre Hospitality Solutions, a third-party provider, experienced unauthorized access to its Central Reservations System (CRS) between November 2016 and March 2017. The breach exposed unencrypted payment card data (card numbers, expiration dates, potentially CVVs) and guest PII (names, emails, addresses) for a subset of reservations. Sabre engaged forensic investigators and law enforcement; access was contained. No evidence of data removal was found, though exfiltration remains possible.
California clockDiscovered Jun 6, 2017 → Notified Jul 20, 201744d ✓ CA 60-day OK6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-100489
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 21, 2017
- Raw hash
- f004306e8e011902155a11fbed98ebc1faf55f75bbb593f2eb855caf6527fa04
Reporting entity
- Name
- Pacific Hospitality Groupnorm: pacific hospitality
- Domain
- phgcorp.com
Victim entity
- Name
- Pacific Hospitality Groupnorm: pacific hospitality
- Domain
- phgcorp.com
Incident
- Discovered
- Jun 6, 2017
- Materiality determined
- —
- Notification sent
- Jul 20, 2017
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 6 weeks(45 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 44d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 6, 2017→ Notified: Jul 20, 201744d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.