HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
Inntopia
bd_0e2ce416aaa7f2ea · schema v1 · pii pii-v1
Full breach record for Inntopia →Sterling Valley Systems d/b/a Inntopia reported an external system breach (hacking) occurring between October 9, 2021, and February 18, 2022, discovered on March 2, 2022. The incident affected 68,635 individuals, including 329 Maine residents. Acquired data included names and financial account or credit/debit card numbers (with security codes/PINs). Inntopia sent written notifications and provided 12 months of credit monitoring and identity theft protection through Experian.
Maine clockDiscovered Mar 2, 2022 → Filed with AG May 23, 202282d ⏱ ME AG >30d12 weeks discovery → filing
⚠ AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_0c1dfe4431a0c3dcCalifornia State AGfiled 2022-05-23Verified
- bd_9668e3d8e4baa4eaMaine State AGfiled 2022-04-12(41d gap)Verified
- bd_3de66c5861cbb88fWashington State AGfiled 2022-04-05(48d gap)Candidate
- bd_4a93c6f54f43e3b4Maine State AGfiled 2022-04-05(48d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 48d gap
- bd_e07f2d66f5ea04c7California State AGfiled 2022-04-05(48d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/c182d8c0-5bc7-40ea-9083-37f169bd217a.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 23, 2022
- Raw hash
- fa73842b39f4f8702f7b097a774f766fd005f29c54ad5e923e92e5f07dced8ce
Reporting entity
- Name
- Inntopianorm: inntopia
- Domain
- inntopia.com
Victim entity
- Name
- Inntopianorm: inntopia
- Domain
- inntopia.com
Incident
- Discovered
- Mar 2, 2022
- Materiality determined
- —
- Notification sent
- Apr 5, 2022
- Affected individuals
- 68,635
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed data breach notice with Maine Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 12 weeks(82 days from discovery to filing)
- Compliance flags
- ME AG >30d · 82d
- Discovery-date grounding
- AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Mar 2, 2022→ Filed with AG: May 23, 202282d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.