Social EngineeringHospitalityStolen CredentialsCapture App DataCustomer Data InvolvedEmployee Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALSHighContained
Aimbridge Hospitality Holdings, LLC
bd_ae241e6da3a9354b · schema v1 · pii pii-v1
Full breach record for Aimbridge Hospitality Holdings, LLC →Aimbridge Hospitality Holdings, LLC disclosed unauthorized access to employee email accounts between January 8 and March 21, 2018. Discovered March 21, 2018, the incident exposed personal information of 13,478 California residents including names, Social Security numbers, financial account information, and credentials. Affected entities included Aimbridge Employee Service Corp., AH 2005 Management, L.P., and Evolution Hospitality, LLC. Notifications mailed June 7, 2018; credit monitoring offered via TransUnion.
California clockDiscovered Mar 21, 2018 → Notified Jun 7, 201878d ✗ CA 60-day late11 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_f0163d88cb1b3a51Montana State AGfiled 2018-06-07Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-136921
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 7, 2018
- Raw hash
- 63dab3d8f1c9c3aa9e46156b1f1142a99fc08d1d5769bfb8b8d4c488f5fe7800
Reporting entity
- Name
- Aimbridge Hospitality Holdings, LLCnorm: aimbridge hospitality
Victim entity
- Name
- Aimbridge Hospitality Holdings, LLCnorm: aimbridge hospitality
- Industry
- Hospitalityllm
Incident
- Discovered
- Mar 21, 2018
- Materiality determined
- —
- Notification sent
- Jun 7, 2018
- Affected individuals
- 13,478
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Phishing
- MITRE ATT&CK
- T1114 Email CollectionT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Provided notice to the California Attorney GeneralProviding notice to consumer reporting agencies as requiredProviding notice to certain other state regulators as required
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 11 weeks(78 days from discovery to filing)
- Compliance flags
- CA 60-day late · 78d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 21, 2018→ Notified: Jun 7, 201878d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.