HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedFINANCIAL_ACCOUNTPIILowContained
The Benjamin Hotel
bd_616d9d252f3f016c · schema v1 · pii pii-v1
Full breach record for The Benjamin Hotel →The Benjamin Hotel, operated by Denihan Hospitality, experienced a data breach involving its Sabre Hospitality Solutions SynXis Central Reservations system. Unauthorized access occurred between August 10, 2016, and March 9, 2017, compromising unencrypted payment card data (cardholder name, number, expiration, potential CVV) and guest PII (name, email, phone, address). Sabre engaged forensic investigators and notified law enforcement and payment card brands.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-101136
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 16, 2017
- Raw hash
- 81e27c67698610661c9ef9977f599229579950a2fd769259f8e835511134b122
Reporting entity
- Name
- Denihan Hospitalitynorm: denihan hospitality
Victim entity
- Name
- The Benjamin Hotelnorm: the benjamin hotel
Incident
- Discovered
- Jun 6, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTPII
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid AccountsT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Third party
- via Sabre Hospitality Solutions
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 10 weeks(71 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.