Four Seasons Hotels Limited
bd_c584c626ce77fb93 · schema v1 · pii pii-v1
Full breach record for Four Seasons Hotels Limited →Four Seasons Hotels Limited notified California residents of a data breach involving its third-party reservation provider, Sabre. An unauthorized party obtained account credentials to Sabre's central reservations system, accessing unencrypted payment card information (cardholder name, number, expiration date, and potentially security code) and basic identity information (name, email, phone, address) for a subset of reservations. The unauthorized access occurred between August 10, 2016, and March 9, 2017. Four Seasons was notified on June 6, 2017. Sabre contained the incident, revoked access, and engaged cybersecurity experts. No evidence of data exfiltration was found, but it remains a possibility. Reservations made directly with Four Seasons were not affected.
J jump to incidentP pin to compareR raw source
Incident timeline
Aug 10, 2016
Begins
Jun 6, 2017
Discovered
Jul 6, 2017
Filed
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Washington State AGbd_9c109ae788ede0202017-07-06Candidate
- New Hampshire State AGbd_d069a6c18b7c98902017-07-06Verified
- Montana State AGbd_a2a27652fbf4a7e82017-07-07 · +1dVerified
- Massachusetts State AGbd_b4720887998d60582017-07-07 · +1dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.