MalwareRansomwareData ExfiltratedData EncryptedRansom DemandedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Crestline
bd_7c15fa108144dedb · schema v1 · pii pii-v1
Full breach record for Crestline →Crestline Hotels & Resorts, LLC reported a ransomware incident occurring between May 25 and May 27, 2020. An unauthorized actor encrypted files and exfiltrated data, threatening to release it. The company secured systems, engaged the FBI, and offered credit monitoring to affected individuals. Specific data types included names and government identifiers.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_f349a826a1e9cb65Montana State AGfiled 2021-04-02Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-539677
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 2, 2021
- Raw hash
- 24a61c81bf0efc8b1503eb1368492adf07bc84454af24efac518719def1e04eb
Reporting entity
- Name
- Crestlinenorm: crestline
- Domain
- crestline.com
Victim entity
- Name
- Crestlinenorm: crestline
- Domain
- crestline.com
Incident
- Discovered
- May 27, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 44 weeks(310 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.