DisclosureLens
MalwareHospitalityHospitalityInfostealerCustomer Data InvolvedPCIFinancial accountFinancial credentialsIdentity (basic)LowContained

Six Continents Hotels

bd_3d49f29564c392be · schema v1 · pii pii-v1

Severity

Low

Discovered

Dec 28, 2016

Filed

Feb 3, 2017

To disclose

5 weeks

Affected

Not disclosed

Linked

7 filings

Confidence

64%
Full breach record for Six Continents Hotels2 incidents on file

InterContinental Hotels Group (IHG) notified guests of a payment card data breach at 12 properties in the Americas. Malware installed on servers processed payment cards used at restaurants and bars between August 1, 2016, and December 20, 2016. The malware captured track data including cardholder name, card number, expiration date, and internal verification code from magnetic stripes. IHG discovered the incident on December 28, 2016, after reports of unauthorized charges. Front desk transactions were not affected. IHG engaged cybersecurity firms, notified law enforcement, and worked with payment card networks to monitor affected cards.

California clockDiscovered Dec 28, 2016Notified Feb 3, 201737d CA 60-day OK5 weeks discovery → filing

Incident timeline

undetected · 149 days
discovery → filing · 5 weeks / 37 days

Aug 1, 2016

Begins

Dec 28, 2016

Discovered

Feb 3, 2017

Filed

This filing is one of 7 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (6) · sorted by filing gap

Show 2 more filingsup to 70d gap

Filing propagation · 7 filings · 6 states

View merged incident ↗

Pattern: first filing Feb 3 (CA), last Apr 14 (OR) — a 70-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.