HackingIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Resort Data Processing
bd_4cccc0c6aa4605c7 · schema v1 · pii pii-v1
Full breach record for Resort Data Processing →Resort Data Processing (RDP) disclosed a security event where an unauthorized actor used compromised vendor credentials to scrape customer reservation data, including names, payment card numbers, CVVs, and expiration dates. The incident occurred between December 25, 2024, and January 22, 2025. RDP engaged forensic investigators, offered one year of credit monitoring via Kroll, and implemented additional system safeguards.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376723.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 23, 2026
- Raw hash
- bec18649ba93b3e8b501ebfb1943ffe9dea040368177e25ec6d5d5b75cc41ccf
Reporting entity
- Name
- Resort Data Processingnorm: resort data processing
- Domain
- resortdata.com
Victim entity
- Name
- Resort Data Processingnorm: resort data processing
- Domain
- resortdata.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.