DisclosureLens
HackingHospitalityHospitalityStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedFinancial accountIdentity (basic)MediumContained

Two Roads Hospitality

bd_033eb295e1ba4716 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jun 6, 2017

Filed

Aug 3, 2017

To disclose

8 weeks

Affected

5,401state residents only

Linked

5 filings

Confidence

70%
Full breach record for Two Roads Hospitality

Two Roads Hospitality, LLC reported a third-party breach involving its reservation vendor, Sabre. Unauthorized access to Sabre's SynXis system occurred between August 10, 2016, and March 9, 2017, exposing payment card data and guest PII for approximately 5,401 Washington residents. Sabre engaged forensic investigators and notified law enforcement.

Incident timeline

undetected · 300 days
discovery → filing · 8 weeks / 58 days

Aug 10, 2016

Begins

Jun 6, 2017

Discovered

Aug 3, 2017

Filed

This filing is one of 5 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (4) · sorted by filing gap

Filing propagation · 5 filings · 5 states

View merged incident ↗
Montana State AGJul 14 · first
Oregon State AGJul 14 · first
California State AGJul 14 · first
Washington State AG+20d · this page

Pattern: first filing Jul 14 (MT), last Aug 3 (WA) — a 20-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.