Two Roads Hospitality
bd_033eb295e1ba4716 · schema v1 · pii pii-v1
Full breach record for Two Roads Hospitality →Two Roads Hospitality, LLC reported a third-party breach involving its reservation vendor, Sabre. Unauthorized access to Sabre's SynXis system occurred between August 10, 2016, and March 9, 2017, exposing payment card data and guest PII for approximately 5,401 Washington residents. Sabre engaged forensic investigators and notified law enforcement.
J jump to incidentP pin to compareR raw source
Incident timeline
Aug 10, 2016
Begins
Jun 6, 2017
Discovered
Aug 3, 2017
Filed
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Massachusetts State AGbd_dfa6f55bdce72d1f2017-07-17 · +17dVerified
- Montana State AGbd_9d3d183c565ed7fd2017-07-14 · +20dCandidate
- Oregon State AGbd_d4fa0624cc590ba92017-07-14 · +20dVerified by operator
- California State AGbd_ebac4c1bc981d3ea2017-07-14 · +20dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing Jul 14 (MT), last Aug 3 (WA) — a 20-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.