HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
Noble House Hotels & Resorts
bd_3966eda285e94dfc · schema v1 · pii pii-v1
Full breach record for Noble House Hotels & Resorts →Noble House Hotels & Resorts disclosed a data breach involving its Sabre Hospitality Solutions SynXis Central Reservations system. Unauthorized access occurred between August 10, 2016, and March 9, 2017. The incident potentially exposed customer payment card information (names, card numbers, expiration dates, security codes) and personal details. Sabre, the third-party provider, engaged forensic investigators and notified the FBI and payment card brands. Noble House notified affected customers via letter, offering guidance on credit monitoring and fraud prevention.
California clockDiscovered May 2, 2017 → Notified Jul 27, 201786d ✗ CA 60-day late12 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_adbc4ace086d6cbeWashington State AGfiled 2017-07-28Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-100646
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 28, 2017
- Raw hash
- 6849a4a2f2ad5251568e9bd4755fb7f28c1ec092d10974e572709ca9651c07af
Reporting entity
- Name
- Noble House Hotels & Resortsnorm: noble house hotels resorts
Victim entity
- Name
- Noble House Hotels & Resortsnorm: noble house hotels resorts
Incident
- Discovered
- May 2, 2017
- Materiality determined
- —
- Notification sent
- Jul 27, 2017
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Regulator citations
- Sabre notified the FBI
- Third party
- via Sabre Hospitality Solutions
- Initial access
- supply_chain
Compliance
- Time to disclose
- 12 weeks(87 days from discovery to filing)
- Compliance flags
- CA 60-day late · 86d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 2, 2017→ Notified: Jul 27, 201786d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.