HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Resort Data Processing
bd_9dcdd5d44158e3b0 · schema v1 · pii pii-v1
Full breach record for Resort Data Processing →Resort Data Processing, Inc., a property management software provider, disclosed a cybersecurity attack on its online booking system used by hotels and resorts. Suspicious activity was detected on June 14, 2021, involving malicious code that acquired credit/debit card information and customer PII (name, address, email) from reservations made between January 2019 and June 2021. The company terminated attacker access, deployed a security patch, and engaged forensic investigators.
California clockDiscovered Jun 14, 2021 → Notified Jul 23, 202139d ✓ CA 60-day OK5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_7ff3dec201037068Oregon State AGfiled 2021-07-22Verified
- bd_26e0d8d5acfcd4f8Montana State AGfiled 2021-07-23(1d gap)Verified
- bd_ccfadf2ce4808112Montana State AGfiled 2021-07-23(1d gap)Verified
- bd_8b312adb02cdb175Montana State AGfiled 2021-07-27(5d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 8d gap
- bd_32db99b757ca2d67Maine State AGfiled 2021-07-14(8d gap)Candidate
- bd_78e25fe4ecbfdb01Washington State AGfiled 2021-07-14(8d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-543186
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 22, 2021
- Raw hash
- 3d8ffac9256e8d3fa8503c41d107b9977d027cda746cd07a07b746c3ef297036
Reporting entity
- Name
- Resort Data Processingnorm: resort data processing
- Domain
- resortdata.com
Victim entity
- Name
- Resort Data Processingnorm: resort data processing
- Domain
- resortdata.com
Incident
- Discovered
- Jun 14, 2021
- Materiality determined
- —
- Notification sent
- Jul 23, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(38 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 39d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 14, 2021→ Notified: Jul 23, 202139d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.