HackingStolen CredentialsCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICHighContained
Hilton Grand Vacations Inc.
bd_ed0f7e2071a2eb30 · schema v1 · pii pii-v1
Full breach record for Hilton Grand Vacations Inc. →Hilton Grand Vacations notified the New Hampshire Attorney General on September 3, 2009, of unauthorized access to credit application data. The breach potentially compromised names, SSNs, and dates of birth for up to 2,304 individuals, including 7 New Hampshire residents. Access began as early as February 2009. The company engaged law enforcement and provided 12 months of free credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2,304 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/hilton-20090903.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 3, 2009
- Raw hash
- 49cb7ad0060cc0480b4d5a205a4c6d39ba1d273d8e9625a96540349b10865341
Reporting entity
- Name
- Hilton Grand Vacations Inc.norm: hilton grand vacations
Victim entity
- Name
- Hilton Grand Vacations Inc.norm: hilton grand vacations
Incident
- Discovered
- Feb 1, 2009
- Materiality determined
- —
- Notification sent
- Sep 3, 2009
- Affected individuals
- 2,304
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 31 weeks(214 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.