HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedPCIFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSIDENTITY_BASICLowContained
Remington Lodging & Hospitality
bd_cb2507defe8d7e16 · schema v1 · pii pii-v1
Full breach record for Remington Lodging & Hospitality →Remington Lodging & Hospitality, LLC reported a data breach affecting its Sabre Hospitality Solutions reservation system. Unauthorized access occurred between August 10, 2016, and March 9, 2017, via stolen account credentials. Payment card data (including CVV) and guest PII were accessed. Sabre engaged forensic investigators and notified law enforcement.
California clockDiscovered Jun 6, 2017 → Notified Jul 14, 201738d ✓ CA 60-day OK6 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_7defb1b8fa5a5331Montana State AGfiled 2017-07-17(1d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-100387
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 18, 2017
- Raw hash
- d0e04326d588779a27a83b469866da8f732aee68fc2deac58aefe63fee1a793b
Reporting entity
- Name
- Remington Lodging & Hospitalitynorm: remington lodging hospitality
Victim entity
- Name
- Remington Lodging & Hospitalitynorm: remington lodging hospitality
Incident
- Discovered
- Jun 6, 2017
- Materiality determined
- —
- Notification sent
- Jul 14, 2017
- Affected individuals
- Not disclosed
- Data types
- PCIFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified law enforcementNotified payment card brands
- Third party
- via Sabre Hospitality Solutions
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 6 weeks(42 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 38d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 6, 2017→ Notified: Jul 14, 201738d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.