Hard Rock
bd_0caa99fc6482b75e · schema v1 · pii pii-v1
Full breach record for Hard Rock →Hard Rock International reported a security incident involving its third-party provider, Sabre Hospitality Solutions. An unauthorized party gained access to Sabre's SynXis Central Reservations system using valid account credentials between August 10, 2016, and March 9, 2017. The breach exposed unencrypted payment card information (cardholder name, number, expiration date, CVV) and guest reservation details (name, email, phone, address). Sabre engaged a cybersecurity firm, notified law enforcement, and informed payment card brands. The notification was filed with the California Office of the Attorney General on May 17, 2017.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-100145
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 7, 2017
- Raw hash
- caa4d2e3645b6a39c2a7214afd966b67138f9aa71834806fdd9618d814f84253
Reporting entity
- Name
- Hard Rocknorm: hard rock
- Domain
- hardrock.com
Victim entity
- Name
- Hard Rocknorm: hard rock
- Domain
- hardrock.com
Incident
- Discovered
- Jun 6, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTPII
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Third party
- via Sabre Hospitality Solutions
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 4 weeks(31 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.