MalwareRansomwareData ExfiltratedCustomer Data InvolvedPCIFINANCIAL_ACCOUNTLowContained
HYATT HOTELS CORPORATION
bd_bc7429716d81c102 · schema v1 · pii pii-v1
Full breach record for HYATT HOTELS CORPORATION →Hyatt Hotels Corporation disclosed a payment card incident involving malware deployed at certain managed locations (primarily restaurants) between July 30, 2015, and December 8, 2015. The malware collected payment card data (cardholder name, number, expiration, verification code). Hyatt engaged third-party security experts, notified law enforcement and payment networks, and offered one year of fraud protection services to affected customers. No other customer information was affected.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_02b089e878b47abdWashington State AGfiled 2016-01-14Candidate
- bd_e41f481fb05b9df9Montana State AGfiled 2016-01-14Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-59630
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 14, 2016
- Raw hash
- ecb570c0b56287e6b3e2e1acdf3c1c09a323b04a055a7850528f94ad9049844c
Reporting entity
- Name
- HYATT HOTELS CORPORATIONnorm: hyatt hotels
Victim entity
- Name
- HYATT HOTELS CORPORATIONnorm: hyatt hotels
Incident
- Discovered
- Aug 13, 2015
- Materiality determined
- Jan 14, 2016
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PCIFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 22 weeks(154 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.