sbe
bd_61539978b5411ff8 · schema v1 · pii pii-v1
Full breach record for sbe →SBE ENT Holdings, LLC reported a data security incident involving its third-party provider, Sabre Hospitality Solutions. Unauthorized parties accessed Sabre's SynXis central reservations system using stolen credentials between August 10, 2016, and March 9, 2017. The breach exposed unencrypted payment card information (cardholder name, number, expiration, and potentially CVV) and guest reservation details (name, email, phone, address). Sabre engaged forensic investigators, notified law enforcement and card brands, and implemented measures to stop access. SBE notified affected guests via consumer notice.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-100530
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 22, 2017
- Raw hash
- 86e70a35fe7b6e1a50e8e8e8ff9f023a1397dcf2948c03207e35622f37eafa26
Reporting entity
- Name
- sbe
- Domain
- sbe.com
Victim entity
- Name
- sbe
- Domain
- sbe.com
Incident
- Discovered
- Jun 6, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Third party
- via Sabre Hospitality Solutions
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 7 weeks(46 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.