MalwareRansomwareData ExfiltratedData EncryptedFINANCIAL_ACCOUNTPIILowContained
Atlantis, Paradise Island
bd_a51f13dd392b3a62 · schema v1 · pii pii-v1
Full breach record for Atlantis, Paradise Island →California AG SB24-65066: Island Hotel Company Limited (Atlantis, Paradise Island) reported a data security incident between March 9, 2016, and October 22, 2016. Malware captured credit and debit card data (card number, expiration, CVV, cardholder name) from POS systems at food and beverage and retail locations. The Resort engaged forensic experts, removed the malware, and implemented additional security procedures. No PIN or SSN data was involved.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-65066
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 23, 2016
- Raw hash
- f3e33456073ed731a24062f33d9ddb6a889402ed10bcc5a6cd4457c6ca409d22
Reporting entity
- Name
- Island Hospitalitynorm: island hospitality
- Domain
- island-hospitality.com
Victim entity
- Name
- Atlantis, Paradise Islandnorm: atlantis paradise island
Incident
- Discovered
- Oct 21, 2016
- Materiality determined
- Nov 21, 2016
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTPII
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Initial access
- external_remote_services
Compliance
- Time to disclose
- 5 weeks(33 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.