HackingCustomer Data InvolvedPIIIDENTITY_BASICFINANCIAL_ACCOUNTPCILowContained
EventConnect
bd_0f31cac49a0926b4 · schema v1 · pii pii-v1
Full breach record for EventConnect →EventConnect experienced unauthorized access to its platform between May 28 and June 2, 2025. The incident exposed hotel reservation data including names, addresses, phone numbers, and emails, with potential exposure of payment card numbers (excluding CVVs). EventConnect detected the activity on May 30, 2025, engaged forensic specialists, secured the platform, and notified affected individuals, offering 24 months of credit monitoring.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_7a1c1c5c0cef3666Iowa State AGfiled 2025-07-07(4d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/eventconnect-20250711.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 11, 2025
- Raw hash
- 7bce8aec13804de0ca9c33cab47a361f1e3c0ae31f0654247f7233c0f48a9723
Reporting entity
- Name
- EventConnectnorm: eventconnect
- Domain
- eventconnect.io
Victim entity
- Name
- EventConnectnorm: eventconnect
- Domain
- eventconnect.io
Incident
- Discovered
- May 30, 2025
- Materiality determined
- —
- Notification sent
- Jul 7, 2025
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNTPCI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Provided courtesy notice to New Hampshire Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(42 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.