HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedFINANCIAL_ACCOUNTLowActive
Inntopia
bd_e07f2d66f5ea04c7 · schema v1 · pii pii-v1
Full breach record for Inntopia →Sterling Valley Systems d/b/a Inntopia, an e-commerce reservation platform, disclosed a breach occurring between October 9, 2021, and February 18, 2022. An unknown actor gained unauthorized access to payment card information (credit/debit numbers). The incident affected at least 64 Rhode Island residents, with notifications sent to individuals in multiple states. Inntopia engaged third-party cybersecurity specialists, notified law enforcement and payment card brands, and offered credit monitoring via Experian. The investigation was ongoing at the time of the notice.
California clockDiscovered Feb 18, 2022 → Notified Apr 5, 202246d ✓ CA 60-day OK7 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_3de66c5861cbb88fWashington State AGfiled 2022-04-05Candidate
- bd_4a93c6f54f43e3b4Maine State AGfiled 2022-04-05Verified
- bd_9668e3d8e4baa4eaMaine State AGfiled 2022-04-12(7d gap)Verified
- bd_0c1dfe4431a0c3dcCalifornia State AGfiled 2022-05-23(48d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 48d gap
- bd_0e2ce416aaa7f2eaMaine State AGfiled 2022-05-23(48d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-552326
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 5, 2022
- Raw hash
- 34540a19e8fd9f2b1509eed82205cd8264cdc21d8241b1d5eceacd0d98830121
Reporting entity
- Name
- Inntopianorm: inntopia
- Domain
- inntopia.com
Victim entity
- Name
- Inntopianorm: inntopia
- Domain
- inntopia.com
Incident
- Discovered
- Feb 18, 2022
- Materiality determined
- —
- Notification sent
- Apr 5, 2022
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- notifying payment card brands and law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(46 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 46d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 18, 2022→ Notified: Apr 5, 202246d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.