HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedMulti-Stage ChainIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumResolved
Highgate Corporate
bd_9b4dcfd87bd7218e · schema v1 · pii pii-v1
Full breach record for Highgate Corporate →Highgate Hotels, L.P. disclosed an incident involving unauthorized access to its network. On March 26, 2024, the company detected unusual activity and contained the incident. An unauthorized entity accessed files and employee email accounts between December 28, 2023, and April 4, 2024. Affected data included names, SSNs, tax IDs, driver's licenses, financial account info, and health information. The company engaged a cybersecurity firm, notified law enforcement, and is offering one year of credit monitoring.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_1af3ba3d19dde8d2New Hampshire State AGfiled 2024-12-06Verified
- bd_b74b1374763a8995Indiana State AGfiled 2024-12-06Verified
- bd_f983399997bb9442Montana State AGfiled 2024-12-06Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-595784
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 6, 2024
- Raw hash
- ff85e1a7d148c6713f933977c286af83f00c1bc32ba96d4f8c8638e98bd64d1f
Reporting entity
- Name
- Highgate Corporatenorm: highgate corporate
- Domain
- highgate.com
Victim entity
- Name
- Highgate Corporatenorm: highgate corporate
- Domain
- highgate.com
Incident
- Discovered
- Mar 26, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email CollectionT1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 36 weeks(255 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.