HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
Woodside Hotels and Resorts
bd_692696f7bcb34fa0 · schema v1 · pii pii-v1
Full breach record for Woodside Hotels and Resorts →Woodside Hotels and Resorts reported a data breach involving its third-party service provider, Sabre Hospitality Solutions. Unauthorized access to the Sabre SynXis Central Reservations system occurred between August 10, 2016, and March 9, 2017. The incident exposed payment card information (names, numbers, expiration dates, CVVs) and guest PII (names, emails, phone numbers, addresses) for a subset of reservations. No Woodside internal systems were compromised. Sabre engaged forensic investigators and notified law enforcement and card brands.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-100577
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 26, 2017
- Raw hash
- 78b9623cbcce06e75a42afafa087ecb448ebad0199469b032d83e0bd072a24ff
Reporting entity
- Name
- Woodside Hotels and Resortsnorm: woodside hotels and resorts
Victim entity
- Name
- Woodside Hotels and Resortsnorm: woodside hotels and resorts
Incident
- Discovered
- Jun 6, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Third party
- via Sabre Hospitality Solutions
- Initial access
- supply_chain
Compliance
- Time to disclose
- 7 weeks(50 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.