DisclosureLens
MalwareHospitalityHospitalityInfostealerData ExfiltratedCustomer Data InvolvedIdentity (basic)Financial accountLowContained

Crowne Plaza Columbus, Ohio

bd_3f0eb77d1bd17ba2 · schema v1 · pii pii-v1

Severity

Low

Discovered

Apr 4, 2012

Filed

May 18, 2012

To disclose

6 weeks

Affected

Not disclosed

Confidence

65%
Full breach record for Crowne Plaza Columbus, Ohio

Crowne Plaza Columbus, Ohio (owned by VWI Operations, LLC, managed by Interstate Management Company, LLC) experienced a malware incident on front desk computers between March 14-23, 2012. Discovered April 4, 2012, the malware likely captured guest names, addresses, and credit card data. The hotel notified law enforcement (Secret Service) and card networks, deactivated infected systems, and implemented employee training.

Incident timeline

undetected · 21 days
discovery → filing · 6 weeks / 44 days

Mar 14, 2012

Begins

Apr 4, 2012

Discovered

May 18, 2012

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.