HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedPCIFINANCIAL_ACCOUNTLowContained
Hutton Hotel
bd_ba75ee2ec2d6f548 · schema v1 · pii pii-v1
Full breach record for Hutton Hotel →Hutton Hotel experienced a data breach involving unauthorized installation of malware on payment processing systems, compromising payment card data (names, account numbers, expiration dates, verification codes) of guests who made reservations or purchases between September 19, 2012, and June 10, 2016. The company engaged a cybersecurity firm, notified law enforcement, and implemented enhanced security measures.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_f19b312dc6394519New Hampshire State AGfiled 2016-09-30Verified
- bd_7583e8c60b231fddMontana State AGfiled 2016-09-29(1d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-64177
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 30, 2016
- Raw hash
- a2a54cad59a982425da622822c5b874f2cc674f554142bc57f83d66ecff39aae
Reporting entity
- Name
- Hutton Hotelnorm: hutton hotel
Victim entity
- Name
- Hutton Hotelnorm: hutton hotel
Incident
- Discovered
- Jun 10, 2016
- Materiality determined
- Sep 28, 2016
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PCIFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 16 weeks(112 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.