HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedPIIFINANCIAL_ACCOUNTLowContained
Resort Data Processing
bd_77ebc3a0c5dafb05 · schema v1 · pii pii-v1
Full breach record for Resort Data Processing →Resort Data Processing, Inc. (RDP) notified the New Hampshire Attorney General on October 27, 2023, of a security incident affecting 271 state residents. Discovered on August 21, 2023, an unauthorized actor exploited a SQL injection vulnerability in clients' Internet Reservation Modules to exfiltrate payment card information. RDP contained the activity on August 23, 2023, patched the vulnerability, engaged forensic investigators, and notified law enforcement. Affected individuals were offered one year of credit monitoring.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_0610ee2684ca6f94Montana State AGfiled 2023-10-27Candidate
- bd_261cdc2d59a3bfacMaine State AGfiled 2023-10-27Verified
- bd_cdde0cb57f086db5Oregon State AGfiled 2023-10-27Verified
- bd_f4095132606e7467Washington State AGfiled 2023-10-27Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/resort-data-processing-20231027.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 27, 2023
- Raw hash
- 6c4ce8168c8594efa42939e77aa408e2dbb923c063007e6f9505b0d6310b6ca2
Reporting entity
- Name
- Resort Data Processingnorm: resort data processing
- Domain
- resortdata.com
Victim entity
- Name
- Resort Data Processingnorm: resort data processing
- Domain
- resortdata.com
Incident
- Discovered
- Aug 21, 2023
- Materiality determined
- —
- Notification sent
- Oct 27, 2023
- Affected individuals
- 271
- Data types
- PIIFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 10 weeks(67 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.