HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedFINANCIAL_ACCOUNTPIILowContained
The Sandman Santa Rosa
bd_1065ef8e57774bf6 · schema v1 · pii pii-v1
Full breach record for The Sandman Santa Rosa →The Sandman Santa Rosa reported a data breach involving its third-party service provider, Sabre Hospitality Solutions. Unauthorized access to the Sabre SynXis Central Reservations system occurred between August 10, 2016, and March 9, 2017. The incident exposed payment card information (names, numbers, expiration dates, CVVs) and guest PII (emails, phone numbers, addresses). No Sandman internal systems were compromised. Sabre engaged forensic investigators and law enforcement.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-100490
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 21, 2017
- Raw hash
- 5722bd87bf86a866bf0c3e8123f623f1b5475d1d93a95f06bf671f52ee629b50
Reporting entity
- Name
- The Sandman Santa Rosanorm: the sandman santa rosa
Victim entity
- Name
- The Sandman Santa Rosanorm: the sandman santa rosa
Incident
- Discovered
- Jun 6, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTPII
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Third party
- via Sabre Hospitality Solutions
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 6 weeks(45 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.