HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALSLowContained
Drury Hotels Company, LLC
bd_4f757c5a26b51926 · schema v1 · pii pii-v1
Full breach record for Drury Hotels Company, LLC →Drury Hotels Company, LLC reported a data breach involving a third-party technology service provider used for third-party online booking reservations. Unauthorized access occurred between December 28, 2017, and June 2, 2019. The incident exposed guest names, addresses, payment card numbers, expiration dates, and verification codes. Drury notified 359 California residents via mail, email, and a press release/website notice. The service provider engaged a cybersecurity firm to investigate and implement security enhancements.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed359 affectedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-179448
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 1, 2019
- Raw hash
- ffd123bd42341d7d824c07a08fde85d3d95e918f9091fb792ba26b69aa2c1059
Reporting entity
- Name
- Drury Hotels Company, LLCnorm: drury hotels
Victim entity
- Name
- Drury Hotels Company, LLCnorm: drury hotels
Incident
- Discovered
- Mar 26, 2019
- Materiality determined
- Oct 1, 2019
- Notification sent
- —
- Affected individuals
- 359
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Initial access
- supply_chain
Compliance
- Time to disclose
- 27 weeks(189 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.