Six Continents Hotels
bd_3d49f29564c392be · schema v1 · pii pii-v1
Full breach record for Six Continents Hotels →2 incidents on fileInterContinental Hotels Group (IHG) notified guests of a payment card data breach at 12 properties in the Americas. Malware installed on servers processed payment cards used at restaurants and bars between August 1, 2016, and December 20, 2016. The malware captured track data including cardholder name, card number, expiration date, and internal verification code from magnetic stripes. IHG discovered the incident on December 28, 2016, after reports of unauthorized charges. Front desk transactions were not affected. IHG engaged cybersecurity firms, notified law enforcement, and worked with payment card networks to monitor affected cards.
J jump to incidentP pin to compareR raw source
Incident timeline
Aug 1, 2016
Begins
Dec 28, 2016
Discovered
Feb 3, 2017
Filed
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- Montana State AGbd_4a76c7e03c62e29d2017-04-14 · +70dVerified
- Massachusetts State AGbd_8c134423752fa0372017-04-14 · +70dVerified
- California State AGbd_8ef72d261a0a28c02017-04-14 · +70dVerified
- Washington State AGbd_bf6597d4b90e06332017-04-14 · +70dVerified
Show 2 more filings ↓Show fewer ↑up to 70d gap
- New Hampshire State AGbd_d66a216b1857d4262017-04-14 · +70dVerified
- Oregon State AGbd_da3308682a4d4c2c2017-04-14 · +70dVerified
Filing propagation · 7 filings · 6 states
View merged incident ↗Pattern: first filing Feb 3 (CA), last Apr 14 (OR) — a 70-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.