MalwarePCIFINANCIAL_ACCOUNTLowContained
Hard Rock Hotel & Casino Las Vegas
bd_38b7093bb534b1e7 · schema v1 · pii pii-v1
Full breach record for Hard Rock Hotel & Casino Las Vegas →Hard Rock Hotel & Casino Las Vegas experienced a payment card breach involving card scraping malware. Unauthorized access occurred between October 27, 2015, and March 21, 2016, with discovery on May 13, 2016. The incident exposed payment card data (card numbers, expiration dates, verification codes). The resort engaged a cybersecurity firm, notified law enforcement, and worked with payment card networks to monitor affected cards. No other customer information was involved.
California clockDiscovered May 13, 2016 → Notified Jun 27, 201645d ✓ CA 60-day OK6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_3a85e72fa11e77b3Washington State AGfiled 2016-06-27Candidate
- bd_6df8ae9e1331002bOregon State AGfiled 2016-06-27Verified
- bd_d50f95ab89e04866Montana State AGfiled 2016-06-27Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-62545
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 27, 2016
- Raw hash
- 48e235776b5f556421b57a8cf57d7422b36218ed71fdb02a3797b559d39e8595
Reporting entity
- Name
- Hard Rock Hotel & Casino Las Vegasnorm: hard rock hotel casino las vegas
Victim entity
- Name
- Hard Rock Hotel & Casino Las Vegasnorm: hard rock hotel casino las vegas
Incident
- Discovered
- May 13, 2016
- Materiality determined
- —
- Notification sent
- Jun 27, 2016
- Affected individuals
- Not disclosed
- Data types
- PCIFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified law enforcement officials
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(45 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 45d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 13, 2016→ Notified: Jun 27, 201645d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.