Preferred Hotel Group
bd_b9283f1173df061d · schema v1 · pii pii-v1
Full breach record for Preferred Hotel Group →Preferred Hotels & Resorts disclosed a data breach involving its third-party service provider, Sabre Hospitality Solutions. An unauthorized party gained access to Sabre's SynXis Central Reservations System using valid user credentials between June 2016 and November 2017. The incident exposed payment card information (card numbers, expiration dates, CVVs) and guest PII (names, emails, phone numbers, addresses) for a subset of reservations. No Preferred network systems were directly compromised. Sabre enhanced security controls and notified law enforcement and payment card brands.
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_0b11bd44018a4b03Washington State AGfiled 2018-03-02Candidate
- bd_92af1cd4dff3ae96Oregon State AGfiled 2018-03-02Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-134170
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 2, 2018
- Raw hash
- f249e6225f43f02184fa8bc062ad89e3146f7b864848c853a4a0227499e63356
Reporting entity
- Name
- Preferred Hotel Groupnorm: preferred hotel
Victim entity
- Name
- Preferred Hotel Groupnorm: preferred hotel
Incident
- Discovered
- Nov 1, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Sabre has notified law enforcement and the payment card brands
- Third party
- via Sabre Hospitality Solutions
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 17 weeks(121 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.