DisclosureLens
HackingOtherStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedPCIFinancial accountIdentity (basic)LowContained

Preferred Hotels & Resorts

bd_24e0474a5c4393b2 · schema v1 · pii pii-v1

Severity

Low

Discovered

Mar 2, 2018

Filed

Mar 2, 2018

To disclose

≤1 day

Affected

20state residents only

Linked

5 filings

Confidence

66%

Preferred Hotels & Resorts notified the NH AG of a third-party breach involving Sabre/SynXis. Unauthorized access to user credentials allowed viewing of reservation data (payment cards, PII) between June 2016 and Nov 2017. Approx 20 NH residents affected. Notifications sent March 2018.

Incident timeline

undetected · 639 days
discovery → filing · ≤1 day / 0 days

Jun 1, 2016

Begins

Mar 2, 2018

Discovered

Mar 2, 2018

Filed

vs. sector median

8 wks faster

This filing is one of 5 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (4) · sorted by filing gap

Filing propagation · 5 filings · 5 states

View merged incident ↗
Washington State AGMar 2 · first
Oregon State AGMar 2 · first
California State AGMar 2 · first
New Hampshire State AGMar 2 · first · this page

Pattern: first filing Mar 2 (WA), last Mar 9 (MA) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.