South Coast Winery Resort& Spa
bd_deb4647f5817a75a · schema v1 · pii pii-v1
Full breach record for South Coast Winery Resort& Spa →South Coast Winery Resort & Spa and Carter Estate Winery Resort reported a data breach involving unauthorized access to the Sabre Hospitality Solutions SynXis Central Reservations system. An unauthorized party gained access to account credentials, exposing unencrypted payment card information (cardholder name, number, expiration, and potentially security code) and guest PII (name, email, phone, address) for a subset of reservations. The breach occurred between August 10, 2016, and March 9, 2017. Sabre engaged a cybersecurity firm and notified law enforcement and payment card brands.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-101137
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 16, 2017
- Raw hash
- b97084a870910bdda8d6778ca3f77e69cd3f03484c774cc9d2d9c81722c0c84e
Reporting entity
- Name
- South Coast Winery Resort& Spanorm: south coast winery resort
- Domain
- southcoastwinery.com
Victim entity
- Name
- South Coast Winery Resort& Spanorm: south coast winery resort
- Domain
- southcoastwinery.com
Incident
- Discovered
- Jun 6, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 10 weeks(71 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.