Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedFINANCIAL_ACCOUNTPIILowContained
ORIENT
bd_4da9d8d43a87c70e · schema v1 · pii pii-v1
Full breach record for ORIENT →Orient-Express Hotels Ltd. notified the New Hampshire Attorney General of a security breach involving unauthorized access to corporate email accounts. The incident, discovered on September 24, 2013, involved phishing attacks targeting employees between July and September 2013. Customer credit card information was compromised. The company notified affected customers and engaged forensic investigators.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/orient-express-hotels-20131220.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 20, 2013
- Raw hash
- 5286e801dd6cd56e1ae8f09d15e3762e149292f5165a96cceaa17d5fca73a0e2
Reporting entity
- Name
- ORIENTnorm: orient
- Domain
- orient-watch.com
Victim entity
- Name
- ORIENTnorm: orient
- Domain
- orient-watch.com
Incident
- Discovered
- Sep 24, 2013
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTPII
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed notification with New Hampshire Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 12 weeks(87 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.