HackingStolen CredentialsCapture Stored DataCustomer Data InvolvedTargetedIDENTITY_BASICPIILowContained
Resort Data Processing
bd_a0e4b4a06e21d23f · schema v1 · pii pii-v1
Full breach record for Resort Data Processing →Resort Data Processing notified the NH AG of a security event where an unauthorized actor injected a malicious script on customer websites to scrape reservation data between Feb 19 and Apr 17, 2025. 35 NH residents were affected. RDP engaged forensic investigators, stopped the script, and offered 24 months of credit monitoring via TransUnion.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_96ce6993e847b9e6Indiana State AGfiled 2025-05-14Candidate
- bd_d61dcb6e96e3a420Maine State AGfiled 2025-05-14Verified
- bd_ddf170b689ea8fa4Oregon State AGfiled 2025-05-14Verified
- bd_f4dce13e49c6cc3fNew Hampshire State AGfiled 2025-03-21(54d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 55d gap
- bd_4c495ff1bf829a51Indiana State AGfiled 2025-03-20(55d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/resort-data-processing-20250514.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 14, 2025
- Raw hash
- c8234cb9f22809161ab705d1591fa9985608dd80ac77fcefdae94b34599785b0
Reporting entity
- Name
- Resort Data Processingnorm: resort data processing
- Domain
- resortdata.com
Victim entity
- Name
- Resort Data Processingnorm: resort data processing
- Domain
- resortdata.com
Incident
- Discovered
- May 14, 2025
- Materiality determined
- —
- Notification sent
- May 14, 2025
- Affected individuals
- 35
- Data types
- IDENTITY_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- ≤1 day(0 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.