DisclosureLens
HackingHospitalityHospitalityStolen CredentialsData ExfiltratedCustomer Data InvolvedPCIIdentity (basic)MediumContained

Bartell Hotels

bd_d730f6a526010473 · schema v1 · pii pii-v1

Severity

Medium

Discovered

May 16, 2014

Filed

Sep 12, 2014

To disclose

17 weeks

Affected · nationwide

55,00018 in this filing

Linked

3 filings

Confidence

65%
Full breach record for Bartell Hotels

Bartell Hotels notified NH AG of a data security event affecting 18 NH residents and up to 55,000 customers nationwide. Unauthorized access to payment card processing systems occurred between Feb 16 and May 13, 2014, at five San Diego-area hotels. Stolen data included card numbers, names, and addresses. Incident contained; forensic investigation engaged; identity monitoring offered.

Incident timeline

undetected · 89 days
discovery → filing · 17 weeks / 119 days

Feb 16, 2014

Begins

May 16, 2014

Discovered

Sep 12, 2014

Filed

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
California State AGAug 29 · first
New Hampshire State AG+14d · this page

Pattern: first filing Aug 29 (CA), last Sep 15 (MA) — a 17-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.