DisclosureLens
MalwareHospitalityHospitalityInfostealerData ExfiltratedFinancial accountFinancial credentialsLowResolved

Omni Hotels & Resorts

bd_6bb224b4a8d4ca76 · schema v1 · pii pii-v1

Severity

Low

Discovered

May 30, 2016

Filed

Jul 13, 2016

To disclose

6 weeks

Affected

435state residents only

Linked

7 filings

Confidence

64%
Full breach record for Omni Hotels & Resorts2 incidents on file

Omni Hotel and Resorts disclosed a malware intrusion affecting point-of-sale systems at certain properties. The malware, active between Dec 23, 2015, and June 14, 2016, collected payment card data (names, numbers, security codes, expiration dates). Discovery occurred on May 30, 2016. The company engaged forensic firms, contained the breach, notified law enforcement, and offered 12 months of identity theft protection.

Incident timeline

undetected · 159 days
discovery → filing · 6 weeks / 44 days

Dec 23, 2015

Begins

May 30, 2016

Discovered

Jul 13, 2016

Filed

This filing is one of 7 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (6) · sorted by filing gap

Show 2 more filingsup to 8d gap

Filing propagation · 7 filings · 7 states

View merged incident ↗

Pattern: first filing Jul 7 (NH), last Jul 21 (OR) — a 14-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.