MalwareCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Mandarin Oriental
bd_5f9e8b0cb8d17f50 · schema v1 · pii pii-v1
Full breach record for Mandarin Oriental →Mandarin Oriental disclosed a malware attack affecting multiple hotel properties globally, including locations in the US, UK, Switzerland, and Hong Kong, between June 18, 2014, and March 12, 2015. The incident resulted in the unauthorized acquisition of guest names and credit card numbers. The company engaged forensic investigators and law enforcement, removed the malware, and offered 12 months of identity protection to affected guests.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-56994
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 10, 2015
- Raw hash
- 1b177f801cf2515d2c04a725502506d1fa81eb8f2812d12919bc1f25e85ff88f
Reporting entity
- Name
- Mandarin Orientalnorm: mandarin oriental
Victim entity
- Name
- Mandarin Orientalnorm: mandarin oriental
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- External
- Regulator citations
- Engaged with law enforcement
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.