MalwareHospitalityCapture App DataInfostealerData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPCIIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowResolved
HILTON WORLDWIDE HOLDINGS INC.
bd_a7c1b60b6a8d4dfd · schema v1 · pii pii-v1
Full breach record for HILTON WORLDWIDE HOLDINGS INC. →Hilton Worldwide disclosed a point-of-sale malware incident affecting payment card data at its hotels. The malware ran during two windows: November 18–December 5, 2014 and April 21–July 27, 2015. Cardholder names, payment card numbers, security codes, and expiration dates were targeted. No addresses or PINs were compromised. Hilton worked with third-party forensic experts, law enforcement, and payment card companies. One year of complimentary credit monitoring through AllClear was offered to affected customers.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_5121296658c0299eWashington State AGfiled 2015-11-24Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-59022
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 24, 2015
- Raw hash
- 7833d6fc3f43842d505a023e4f5446f7e6c186e4ecb08403cfad299886c0f687
Reporting entity
- Name
- HILTON WORLDWIDE HOLDINGS INC.norm: hilton worldwide
Victim entity
- Name
- HILTON WORLDWIDE HOLDINGS INC.norm: hilton worldwide
- Industry
- Hospitalityllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PCIIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1505.001 SQL Stored ProceduresT1056 Input CaptureT1005 Data from Local System
- Threat actor
- ExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.