DisclosureLens
HackingHospitalityHospitalityStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedFinancial accountFinancial credentialsIdentity (basic)LowContained

Pacific Hospitality Group

bd_00ff548071ed5da2 · schema v1 · pii pii-v1

Severity

Low

Discovered

Jun 6, 2017

Filed

Jul 21, 2017

To disclose

6 weeks

Affected

Not disclosed

Confidence

64%
Full breach record for Pacific Hospitality Group

Pacific Hospitality Group notified customers of a data breach involving the Sabre Hospitality Solutions SynXis Central Reservations system. An unauthorized party gained access to account credentials, allowing access to unencrypted payment card information (cardholder name, number, expiration date, and potentially security codes) and reservation details (name, email, phone, address) for a subset of hotel reservations. The breach occurred between August 10, 2016, and March 9, 2017. Pacific Hospitality Group was notified by Sabre on June 6, 2017. Sabre engaged a cybersecurity firm, notified law enforcement and payment card brands, and shut off unauthorized access. No forensic evidence of data removal was found, but it remains a possibility.

California clockDiscovered Jun 6, 2017Notified Jul 20, 201744d CA 60-day OK6 weeks discovery → filing

Incident timeline

undetected · 300 days
discovery → filing · 6 weeks / 45 days

Aug 10, 2016

Begins

Jun 6, 2017

Discovered

Jul 21, 2017

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.