Four Seasons Hotels Limited
bd_c584c626ce77fb93 · schema v1 · pii pii-v1
Full breach record for Four Seasons Hotels Limited →Four Seasons Hotels Limited reported a data breach involving its third-party provider, Sabre Hospitality Solutions. Unauthorized parties accessed unencrypted payment card information and reservation data via stolen credentials in Sabre's central reservations system between August 10, 2016, and March 9, 2017. The incident was contained on June 6, 2017. Affected data included cardholder names, card numbers, expiration dates, and potentially security codes, as well as guest contact details. No government IDs were accessed. Sabre engaged forensic investigators and notified law enforcement and credit card brands.
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_9c109ae788ede020Washington State AGfiled 2017-07-06Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-100118
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 6, 2017
- Raw hash
- 6774d99a7e71e6bece35d25c0aabc4b914d0fb1285fb4de72a94e73c36f061ee
Reporting entity
- Name
- Four Seasons Hotels Limitednorm: four seasons hotels
Victim entity
- Name
- Four Seasons Hotels Limitednorm: four seasons hotels
Incident
- Discovered
- Jun 6, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.