Social EngineeringHospitalityHospitalityPhishingStolen CredentialsCustomer Data InvolvedTargetedIdentity (basic)LowContained
Holiday by Atria
bd_c240aea7a3b6eafc · schema v1 · pii pii-v1
Full breach record for Holiday by Atria →Holiday by Atria reported a phishing incident affecting two employee email accounts. Unauthorized access occurred July 28–Aug 4, 2023. 656 Washington residents' names and DOBs were exposed. Notifications mailed Nov 3, 2023. Technical safeguards enhanced.
J jump to incidentP pin to compareR raw source
Washington clock✗ WA AG >90d13 weeks discovery → filing
⚠ AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
Incident timeline
undetected · 7 days
discovery → filing · 13 weeks / 91 days
Jul 28, 2023
Begins
Aug 4, 2023
Discovered
Nov 3, 2023
Filed
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed656 affectedView incident
Evidence ladder
Leak-site claim
Attacker assertion only. Establishes: claim date, group, alleged victim.
Press / market report
Unlocks: incident narrative, operational impact. Still no compliance clock.
State AG / regulator filingThis record
Unlocks: discovery date, data types, affected count, compliance clock.
SEC 8-K / victim statement
Unlocks: materiality, stated response, full audit trail. Ceiling removed.