Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHighContained
Aimbridge Hospitality Holdings, LLC
bd_e48eb334deda60f6 · schema v1 · pii pii-v1
Full breach record for Aimbridge Hospitality Holdings, LLC →Aimbridge Hospitality Holdings, LLC reported a phishing incident affecting employee email accounts between June 7 and September 24, 2018. The breach exposed personal information of 17,381 California residents, including names, SSNs, financial account numbers, and driver's license numbers. Aimbridge reset passwords, implemented MFA, and provided one year of credit monitoring.
California clockDiscovered Sep 14, 2018 → Notified Dec 31, 2018108d ✗ CA 60-day late16 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_a7120229d278b142Oregon State AGfiled 2018-12-31(2d gap)Candidate
- bd_bdeac05efe79abd2Montana State AGfiled 2018-12-31(2d gap)Verified
- bd_f19008c3ce056851Washington State AGfiled 2018-12-31(2d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-143451
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 2, 2019
- Raw hash
- b3c3b2cc313faa6b1a384bf2b2b998498edac482fc1113ccdd98f42e9024dcac
Reporting entity
- Name
- Aimbridge Hospitality Holdings, LLCnorm: aimbridge hospitality
Victim entity
- Name
- Aimbridge Hospitality Holdings, LLCnorm: aimbridge hospitality
Incident
- Discovered
- Sep 14, 2018
- Materiality determined
- —
- Notification sent
- Dec 31, 2018
- Affected individuals
- 17,381
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 16 weeks(110 days from discovery to filing)
- Compliance flags
- CA 60-day late · 108d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 14, 2018→ Notified: Dec 31, 2018108d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.