DisclosureLens
HackingTechnologyInformationVulnerability ExploitData ExfiltratedCustomer Data InvolvedPIIFinancial accountLowContained

Resort Data Processing

bd_77ebc3a0c5dafb05 · schema v1 · pii pii-v1

Severity

Low

Discovered

Aug 21, 2023

Filed

Oct 27, 2023

To disclose

10 weeks

Affected

271state residents only

Linked

9 filings

Confidence

67%
Full breach record for Resort Data Processing4 incidents on file

Resort Data Processing, Inc. (RDP) notified the New Hampshire Attorney General on October 27, 2023, of a security incident affecting 271 state residents. Discovered on August 21, 2023, an unauthorized actor exploited a SQL injection vulnerability in clients' Internet Reservation Modules to exfiltrate payment card information. RDP contained the activity on August 23, 2023, patched the vulnerability, engaged forensic investigators, and notified law enforcement. Affected individuals were offered one year of credit monitoring.

Incident timeline

discovery → filing · 10 weeks / 67 days

Aug 21, 2023

Discovered

Oct 27, 2023

Filed

vs. sector median

9 wks faster

This filing is one of 9 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (8) · sorted by filing gap

Show 4 more filingsup to 299d gap

Filing propagation · 9 filings · 9 states

View merged incident ↗

Pattern: first filing Jan 1 (IL), last Oct 27 (NH) — a 299-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.