HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
Resort Data Processing
bd_32db99b757ca2d67 · schema v1 · pii pii-v1
Full breach record for Resort Data Processing →Resort Data Processing, Inc. reported a cybersecurity incident occurring between February 22, 2021, and June 14, 2021. The breach involved unauthorized access by hackers using malicious code, resulting in the exposure of names and financial account numbers (including credit/debit card numbers with security codes/PINs). A total of 9,790 individuals were affected, including 148 Maine residents. Written notification was sent to consumers on July 14, 2021. No identity theft protection services were offered.
Maine clockDiscovered Jun 14, 2021 → Filed with AG Jul 14, 202130d ✓ ME AG ≤30d4 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_78e25fe4ecbfdb01Washington State AGfiled 2021-07-14Verified
- bd_7ff3dec201037068Oregon State AGfiled 2021-07-22(8d gap)Verified
- bd_9dcdd5d44158e3b0California State AGfiled 2021-07-22(8d gap)Verified
- bd_26e0d8d5acfcd4f8Montana State AGfiled 2021-07-23(9d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 13d gap
- bd_ccfadf2ce4808112Montana State AGfiled 2021-07-23(9d gap)Verified
- bd_8b312adb02cdb175Montana State AGfiled 2021-07-27(13d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/1e350979-c023-4916-9305-8ac99bf6d14b.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 14, 2021
- Raw hash
- 331837af8f3e1e8588e74f7e7b3fb383bcfc7d8e1ed45ff2f9f4a88e62114b30
Reporting entity
- Name
- Resort Data Processingnorm: resort data processing
- Domain
- resortdata.com
Victim entity
- Name
- Resort Data Processingnorm: resort data processing
- Domain
- resortdata.com
Incident
- Discovered
- Jun 14, 2021
- Materiality determined
- —
- Notification sent
- Jul 14, 2021
- Affected individuals
- 9,790
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed data breach notice with Maine Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Jun 14, 2021→ Filed with AG: Jul 14, 202130d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.