HackingStolen CredentialsCustomer Data InvolvedCREDENTIALSIDENTITY_BASICBEHAVIORLowContained
PREFERRED TRAVEL GROUP
bd_ce29bdb59ac2cebf · schema v1 · pii pii-v1
Full breach record for PREFERRED TRAVEL GROUP →Preferred Travel Group disclosed that an unauthorized third party accessed I Prefer loyalty program accounts between June 15 and July 10, 2024. The incident involved the compromise of login credentials (username and password), loyalty points, and hotel reservation information. The company detected suspicious activity on July 10, 2024, and subsequently contained the incident by forcing password resets, enhancing security safeguards, and suspending reward redemptions. Law enforcement was notified.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-594479
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 6, 2024
- Raw hash
- 80ca44e108f0f871965b9188c934d9eee558f5e4c4c650072bf28d80f8f57bc2
Reporting entity
- Name
- PREFERRED TRAVEL GROUPnorm: preferred travel
Victim entity
- Name
- PREFERRED TRAVEL GROUPnorm: preferred travel
Incident
- Discovered
- Jul 10, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALSIDENTITY_BASICBEHAVIOR
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified law enforcement of this incident
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 17 weeks(119 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.