The Domain Hotel Sunnyvale
bd_9ea068369df7b390 · schema v1 · pii pii-v1
Full breach record for The Domain Hotel Sunnyvale →The Domain Hotel, a hospitality provider in Sunnyvale, California, disclosed a data breach involving its third-party reservation service provider, Sabre Hospitality Solutions. Between August 10, 2016, and March 9, 2017, an unauthorized party accessed Sabre's central reservations system, viewing credit card summary pages for certain hotel reservations. The Domain Hotel learned of the incident on July 12, 2017. Affected data included cardholder names, card numbers, expiration dates, and potentially card security codes, along with guest contact information. No Social Security numbers or government IDs were involved. The hotel notified affected guests and worked with Sabre to improve data security. Sabre notified law enforcement and credit bureaus.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-101403
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 28, 2017
- Raw hash
- 8648e6a7afa4cf9bdccc1d952976bfa95d73185e5f33855774e5513ffa4e9b5c
Reporting entity
- Name
- The Domain Hotel Sunnyvalenorm: the domain hotel sunnyvale
- Domain
- domainhotelsv.com
Victim entity
- Name
- The Domain Hotel Sunnyvalenorm: the domain hotel sunnyvale
- Domain
- domainhotelsv.com
Incident
- Discovered
- Jul 12, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Sabre notified law enforcementSabre notified the major credit bureausSabre notified the payment card brands
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(47 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.