Kimpton Hotels & Restaurants
bd_66a20c8443402476 · schema v1 · pii pii-v1
Kimpton Hotels & Restaurants notified customers of a payment card incident involving malware installed on servers processing card data at hotel restaurants and front desks. Unauthorized access occurred between Feb 16 and July 7, 2016. The company discovered the incident on July 15, 2016, hired forensic firms, notified law enforcement, and resolved the issue by August 31, 2016.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 16, 2016
Begins
Jul 15, 2016
Discovered
Aug 31, 2016
Filed
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- New Hampshire State AGbd_25c3a8096ec671072016-08-31Verified
- California State AGbd_5c5e32376e6ba57e2016-08-31Verified
- Massachusetts State AGbd_c9a4a7165c15ae5f2016-09-06 · +6dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing Aug 31 (NH), last Sep 6 (MA) — a 6-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.