HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedFINANCIAL_ACCOUNTPIILowContained
Aqua-Aston Hospitality
bd_3126e42c4aaffcf7 · schema v1 · pii pii-v1
Full breach record for Aqua-Aston Hospitality →Aqua-Aston Hospitality LLC reported a data breach involving the Sabre Hospitality Solutions SynXis Central Reservations system. Unauthorized access occurred between August 10, 2016, and March 9, 2017, compromising unencrypted payment card information (cardholder name, number, expiration, security code) and reservation details for a subset of customers. Sabre, the third-party provider, notified Aqua-Aston on June 8, 2017. No SSN, passport, or driver's license data was accessed. Sabre engaged forensic investigators and notified law enforcement and payment card brands.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-100304
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 14, 2017
- Raw hash
- 3e2d0462500292e0063010cea4db8dd27126b6574f58fc055d604dbf35fb242f
Reporting entity
- Name
- Aqua-Aston Hospitalitynorm: aqua aston hospitality
Victim entity
- Name
- Aqua-Aston Hospitalitynorm: aqua aston hospitality
Incident
- Discovered
- Jun 8, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 5 weeks(36 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.