HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedFINANCIAL_ACCOUNTLowActive
Inntopia
bd_0c1dfe4431a0c3dc · schema v1 · pii pii-v1
Full breach record for Inntopia →Sterling Valley Systems d/b/a Inntopia disclosed a breach affecting payment card information for approximately 58 Rhode Island residents (and potentially others in DC, MD, NM, NY, NC). The incident occurred between October 9, 2021, and February 18, 2022, when an unknown actor accessed payment card data on Inntopia's e-commerce reservation platform. Inntopia engaged third-party cybersecurity specialists, notified law enforcement and payment card brands, and offered credit monitoring services.
California clockDiscovered Feb 18, 2022 → Notified May 23, 202294d ✗ CA 60-day late13 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_0e2ce416aaa7f2eaMaine State AGfiled 2022-05-23Verified
- bd_9668e3d8e4baa4eaMaine State AGfiled 2022-04-12(41d gap)Verified
- bd_3de66c5861cbb88fWashington State AGfiled 2022-04-05(48d gap)Candidate
- bd_4a93c6f54f43e3b4Maine State AGfiled 2022-04-05(48d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 48d gap
- bd_e07f2d66f5ea04c7California State AGfiled 2022-04-05(48d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-553641
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 23, 2022
- Raw hash
- 7befe871a8b2f09c09ebc34c7df88f4dc4de5c256ce301853bbf283213feae53
Reporting entity
- Name
- Inntopianorm: inntopia
- Domain
- inntopia.com
Victim entity
- Name
- Inntopianorm: inntopia
- Domain
- inntopia.com
Incident
- Discovered
- Feb 18, 2022
- Materiality determined
- —
- Notification sent
- May 23, 2022
- Affected individuals
- 58
- Data types
- FINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- notifying payment card brands and law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 13 weeks(94 days from discovery to filing)
- Compliance flags
- CA 60-day late · 94d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 18, 2022→ Notified: May 23, 202294d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.