Resort Data Processing
bd_d61dcb6e96e3a420 · schema v1 · pii pii-v1
Full breach record for Resort Data Processing →4 incidents on fileResort Data Processing (RDP) disclosed an external system breach where an unauthorized actor injected a malicious script to scrape customer reservation data, including names, payment card numbers, CVVs, and expiration dates. The incident affected 5,007 individuals, including 44 Maine residents, between February 19 and April 17, 2025. RDP engaged forensic investigators and offered 12 months of TransUnion credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 19, 2025
Begins
Apr 23, 2025
Discovered
May 14, 2025
Filed
vs. sector median
16 wks faster
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- Indiana State AGbd_96ce6993e847b9e62025-05-14Candidate
- New Hampshire State AGbd_a0e4b4a06e21d23f2025-05-14Verified
- Oregon State AGbd_ddf170b689ea8fa42025-05-14Verified
- Nebraska State AGbd_f4a978a89704c9482025-05-14Verified
Show 5 more filings ↓Show fewer ↑up to 55d gap
- Massachusetts State AGbd_92132c96d31f711e2025-05-15 · +1dVerified
- Massachusetts State AGbd_7dd00237ee453ab12025-03-21 · +54dVerified
- New Hampshire State AGbd_f4dce13e49c6cc3f2025-03-21 · +54dVerified
- Nebraska State AGbd_1196423476f86fb92025-03-20 · +55dVerified
- Indiana State AGbd_4c495ff1bf829a512025-03-20 · +55dCandidate
Filing propagation · 10 filings · 6 states
View merged incident ↗Pattern: first filing Mar 20 (NE), last May 15 (MA) — a 56-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.