Luxury Retreats
bd_065bf0a7254f68f4 · schema v1 · pii pii-v1
Luxury Retreats notified the NH AG of a security incident where an unknown individual gained unauthorized access to an employee's corporate email account on March 22, 2018. The actor used the account to send spam. Customer PII (name, address, DOB, payment card, CVV, financial account, driver's license, passport) was present in the account. Only 2 NH residents were notified. No evidence of data misuse was found.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 22, 2018
Discovered
May 24, 2018
Filed
vs. sector median
+1 wks slower
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.