HILTON WORLDWIDE HOLDINGS INC.
bd_25af5c6d17500973 · schema v1 · pii pii-v1
Full breach record for HILTON WORLDWIDE HOLDINGS INC. →Hilton Worldwide disclosed unauthorized malware targeting payment card information (cardholder names, numbers, security codes, expiration dates) in point-of-sale systems at hotels. The malware operated between Nov 2014 and July 2015. Hilton engaged forensic experts and law enforcement, eradicated the malware, and offered one year of credit monitoring. No PINs or addresses were compromised. The specific number of affected individuals was not disclosed.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 18, 2014
Begins
Nov 24, 2015
Discovered
Dec 3, 2015
Filed
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Washington State AGbd_5121296658c0299e2015-11-24 · +9dCandidate
- Massachusetts State AGbd_5b9bdc8464cf74622015-11-24 · +9dVerified
- Montana State AGbd_78dc814dedd567522015-11-24 · +9dVerified
- California State AGbd_a7c1b60b6a8d4dfd2015-11-24 · +9dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing Nov 24 (WA), last Dec 3 (SC) — a 9-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.