Preferred Hotel Group
bd_82c19e2c59c9cc9d · schema v1 · pii pii-v1
Full breach record for Preferred Hotel Group →Preferred Hotel Group, Inc. reported a data breach involving its third-party provider, Sabre Hospitality Solutions. Unauthorized access occurred between August 10, 2016, and March 9, 2017, affecting a subset of hotel reservations. The breach exposed unencrypted payment card information (cardholder name, number, expiration, potential security code) and guest PII (name, email, phone, address). No SSN, passport, or driver's license data was accessed. The incident was discovered on June 6, 2017, following Sabre's forensic investigation. Response actions included notifying law enforcement, payment card brands, and credit reporting agencies, and working with Sabre to improve security processes.
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_7b0ec09ba7023e8dOregon State AGfiled 2017-07-07(7d gap)Verified by operator
- bd_7ce5af2e70d11e69Montana State AGfiled 2017-07-06(8d gap)Verified by operator
- bd_7bd155a5cc2ba53aWashington State AGfiled 2017-06-30(14d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-100315
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 14, 2017
- Raw hash
- 83f669955cc9e9a6edd176ceecb99969715b3b841df3ddcbb2544535b4933c5f
Reporting entity
- Name
- Preferred Hotel Groupnorm: preferred hotel
Victim entity
- Name
- Preferred Hotel Groupnorm: preferred hotel
Incident
- Discovered
- Jun 6, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Regulator citations
- Submitted breach notification to California Office of the Attorney General
- Third party
- via Sabre Hospitality Solutions
- Initial access
- external_remote_services
Compliance
- Time to disclose
- 5 weeks(38 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.