MalwarePCIFINANCIAL_ACCOUNTLowContained
Rosen Hotels & Resorts
bd_b16dffb998cfb400 · schema v1 · pii pii-v1
Full breach record for Rosen Hotels & Resorts →Rosen Hotels & Resorts, Inc. disclosed a payment card malware incident affecting cards used between September 2, 2014, and February 18, 2016. Malware installed in the payment card network captured magnetic stripe data, including card numbers and verification codes. The company engaged a cybersecurity firm, worked with payment networks, and supported law enforcement. Enhanced security measures were implemented.
California clockDiscovered Feb 3, 2016 → Notified Mar 4, 201630d ✓ CA 60-day OK4 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_4f7660b0923ac5edMontana State AGfiled 2016-03-04Candidate
- bd_cc33a49c08666b86New Hampshire State AGfiled 2016-03-04Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-60301
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 4, 2016
- Raw hash
- 594d205105d4e7bcd7278e82ad6ce6183d32a82aa1e4cb29123bf5a44d0d54b2
Reporting entity
- Name
- Rosen Hotels & Resortsnorm: rosen hotels resorts
- Domain
- rosenhotels.com
Victim entity
- Name
- Rosen Hotels & Resortsnorm: rosen hotels resorts
- Domain
- rosenhotels.com
Incident
- Discovered
- Feb 3, 2016
- Materiality determined
- —
- Notification sent
- Mar 4, 2016
- Affected individuals
- Not disclosed
- Data types
- PCIFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- supporting law enforcement’s investigation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 3, 2016→ Notified: Mar 4, 201630d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.