DisclosureLens
HackingHospitalityHospitalityStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedPIIPCIIdentity (basic)Financial accountFinancial credentialsLowContained

Hard Rock Hotel San Diego

bd_33847a9c19344e3f · schema v1 · pii pii-v1

Severity

Low

Discovered

Jun 6, 2017

Filed

Aug 24, 2017

To disclose

11 weeks

Affected

10state residents only

Confidence

65%

Hard Rock Hotel San Diego notified guests of a data breach involving third-party vendor Sabre Hospitality Solutions. Unauthorized access to unencrypted payment card info and reservation data occurred between Aug 10, 2016 and Mar 9, 2017. Sabre was notified on June 6, 2017. Data included names, card numbers, and security codes. Sabre engaged forensic investigators and notified law enforcement.

Incident timeline

undetected · 300 days
discovery → filing · 11 weeks / 79 days

Aug 10, 2016

Begins

Jun 6, 2017

Discovered

Aug 24, 2017

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed10 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.