DisclosureLens
HackingHospitalityHospitalityStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedFinancial accountFinancial credentialsIdentity (basic)LowContained

Hard Rock

bd_0caa99fc6482b75e · schema v1 · pii pii-v1

Severity

Low

Discovered

Jun 6, 2017

Filed

Jul 7, 2017

To disclose

4 weeks

Affected

Not disclosed

Linked

4 filings

Confidence

64%
Full breach record for Hard Rock

Hard Rock International notified customers of a security incident involving Sabre Hospitality Solutions, a third-party reservation system provider. An unauthorized party gained access to account credentials, allowing access to unencrypted payment card information (card number, expiration, CVV) and reservation details (name, email, phone, address) for a subset of hotel reservations. Access occurred between August 10, 2016, and March 9, 2017. Sabre notified Hard Rock on June 6, 2017, and engaged a cybersecurity firm and law enforcement.

California clockDiscovered Jun 6, 2017Notified Jun 27, 201721d CA 60-day OK4 weeks discovery → filing

Incident timeline

undetected · 300 days
discovery → filing · 4 weeks / 31 days

Aug 10, 2016

Begins

Jun 6, 2017

Discovered

Jul 7, 2017

Filed

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 4 states

View merged incident ↗
Montana State AGJul 7 · first
California State AGJul 7 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.