HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
The Roosevelt Hotel New York
bd_3aef975ad628bcb7 · schema v1 · pii pii-v1
Full breach record for The Roosevelt Hotel New York →The Roosevelt Hotel New York disclosed a data breach involving its third-party reservation provider, Sabre Hospitality Solutions. Between August 10, 2016, and March 9, 2017, unauthorized parties accessed Sabre's system, viewing credit card summary pages (cardholder name, number, expiration, security code) and guest contact info for certain reservations. The hotel learned of the incident on July 12, 2017. No SSN or government IDs were involved. Sabre notified law enforcement and credit bureaus.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-101407
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 28, 2017
- Raw hash
- 28d587dc1b2155e7266652859f1f664fbd17a7b328ddb941f891bdc3e8f86148
Reporting entity
- Name
- The Roosevelt Hotel New Yorknorm: the roosevelt hotel new york
- Industry
- hospitality
Victim entity
- Name
- The Roosevelt Hotel New Yorknorm: the roosevelt hotel new york
- Industry
- hospitality
Incident
- Discovered
- Jul 12, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Third party
- via Sabre Hospitality Solutions
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 7 weeks(47 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.