HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)FINANCIAL_ACCOUNTPIILowContained
South Coast Winery Resort& Spa
bd_83286efbb193ef57 · schema v1 · pii pii-v1
Full breach record for South Coast Winery Resort& Spa →South Coast Winery Resort & Spa and Carter Estate Winery Resort reported a data breach involving their third-party reservations provider, Sabre. Unauthorized access to the Sabre SynXis Central Reservations system occurred between August 10, 2016, and March 9, 2017. The attacker accessed unencrypted payment card information (cardholder name, number, expiration, and potentially security code) and guest PII (name, email, phone, address). Sabre engaged forensic investigators and notified law enforcement and payment card brands.
California clockDiscovered Jun 6, 2017 → Notified Aug 18, 201773d ✗ CA 60-day late12 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-101480
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 30, 2017
- Raw hash
- 54a23a623994998df9bbaff21ac68596536c919a7eb74e81c2b6386bbf413204
Reporting entity
- Name
- South Coast Winery Resort& Spanorm: south coast winery resort
- Domain
- southcoastwinery.com
Victim entity
- Name
- South Coast Winery Resort& Spanorm: south coast winery resort
- Domain
- southcoastwinery.com
Incident
- Discovered
- Jun 6, 2017
- Materiality determined
- —
- Notification sent
- Aug 18, 2017
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTPII
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Third party
- via Sabre Hospitality Solutions
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 12 weeks(85 days from discovery to filing)
- Compliance flags
- CA 60-day late · 73d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 6, 2017→ Notified: Aug 18, 201773d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.