DisclosureLens
MalwareHospitalityHospitalitySkimmerData ExfiltratedCustomer Data InvolvedPCIFinancial accountFinancial credentialsIdentity (basic)MediumContained

Noble House Hotels & Resorts

bd_7f17a96003d1419e · schema v1 · pii pii-v1

Severity

Medium

Discovered

Aug 19, 2016

Filed

Sep 2, 2016

To disclose

14 days

Affected

1,463state residents only

Linked

9 filings

Confidence

68%
Full breach record for Noble House Hotels & Resorts3 incidents on file

Noble House Hotels & Resorts notified the Washington AG of a cyberattack involving skimmers/malware on payment processing systems at multiple properties. Unauthorized access occurred between April 25 and August 3, 2016. The incident compromised PCI data (card numbers, CVVs) for 1,463 Washington residents. Notification began September 2, 2016.

Incident timeline

undetected · 116 days
discovery → filing · 14 days

Apr 25, 2016

Begins

Aug 19, 2016

Discovered

Sep 2, 2016

Filed

This filing is one of 9 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (8) · sorted by filing gap

Show 4 more filingsup to 9d gap

Filing propagation · 9 filings · 6 states

View merged incident ↗

Pattern: first filing Aug 24 (MT), last Sep 2 (WA) — a 9-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.