HackingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Hudson River Partners I L.P.
bd_12aa427de683d475 · schema v1 · pii pii-v1
Full breach record for Hudson River Partners I L.P. →The Historic Thayer Hotel experienced unauthorized access to its computer systems on September 19, 2025. The incident exposed names combined with driver's license numbers, passport numbers, dates of birth, state ID numbers, and potentially Social Security numbers for US residents. The hotel engaged third-party forensic specialists, notified law enforcement, and is providing 12 months of credit monitoring via Kroll Security. No identity theft or fraud has been observed to date.
California clockDiscovered Sep 19, 2025 → Notified Oct 31, 202542d ✓ CA 60-day OK6 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_5ff7442183fae9c4Indiana State AGfiled 2025-11-03Verified
- bd_7e2139f3f98129d0Maine State AGfiled 2025-11-03Verified
- bd_fed038a81b8b76acVermont State AGfiled 2025-11-03Verified
- bd_d48218c6d02db346Texas State AGfiled 2025-11-04(1d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 3d gap
- bd_21fe280fdcbdc5b0New Hampshire State AGfiled 2025-11-05(2d gap)Verified
- bd_8009cd56be9477b8Montana State AGfiled 2025-10-31(3d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-613747
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 3, 2025
- Raw hash
- 381bdb96d0846ba5aac68fb5b74867e6ec31eb091865396a7083ddfa272f3833
Reporting entity
- Name
- Hudson River Partners I L.P.norm: hudson river partners i
- Domain
- thethayerhotel.com
Victim entity
- Name
- Hudson River Partners I L.P.norm: hudson river partners i
- Domain
- thethayerhotel.com
Incident
- Discovered
- Sep 19, 2025
- Materiality determined
- —
- Notification sent
- Oct 31, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unknown
- Threat actor
- External
- Regulator citations
- Notifying appropriate regulators and others as required by governing law
Compliance
- Time to disclose
- 6 weeks(45 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 42d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 19, 2025→ Notified: Oct 31, 202542d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.