MalwareRansomwareData ExfiltratedData EncryptedFINANCIAL_ACCOUNTCREDENTIALSLowContained
Omni Hotels & Resorts
bd_870a61eb6495f324 · schema v1 · pii pii-v1
Full breach record for Omni Hotels & Resorts →Omni Hotels & Resorts reported a malware intrusion affecting point-of-sale systems at select properties between December 23, 2015, and June 14, 2016. The malware collected payment card data (names, numbers, security codes, expiration dates). The company engaged forensic investigators, contained the intrusion, and notified law enforcement. No evidence of other customer data (SSN, contact info) being affected. 12 months of identity theft protection offered.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_ef2dadbfc98e5e4eMontana State AGfiled 2016-07-08Candidate
- bd_a32dcecca74361adOregon State AGfiled 2016-07-21(13d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-62753
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 8, 2016
- Raw hash
- 55c18ae691f393cbf8b7fe61819730565c2d789aa1d341ecdb1454ddc7a44c30
Reporting entity
- Name
- Omni Hotels & Resortsnorm: omni hotels resorts
- Domain
- omnihotels.com
Victim entity
- Name
- Omni Hotels & Resortsnorm: omni hotels resorts
- Domain
- omnihotels.com
Incident
- Discovered
- May 30, 2016
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(39 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.