HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
Kimpton Hotels & Restaurants
bd_f9071946d36b9e1a · schema v1 · pii pii-v1
Full breach record for Kimpton Hotels & Restaurants →Kimpton Hotels & Restaurants notified customers of a third-party data breach involving Sabre Hospitality Solutions SynXis Central Reservations system. Unauthorized access occurred between August 10, 2016, and March 9, 2017. The incident involved payment card data (names, card numbers, expiration dates, CVV) and contact information. Kimpton confirmed Sabre's investigation with a digital forensics firm and notified law enforcement and payment card brands. No specific number of affected individuals was disclosed in this filing.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-100657
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 28, 2017
- Raw hash
- 3dc12647e5fa49fa5e4e8f5db7503ece8a66dc26300787746178e15cc6e89a22
Reporting entity
- Name
- Kimpton Hotels & Restaurantsnorm: kimpton hotels restaurants
Victim entity
- Name
- Kimpton Hotels & Restaurantsnorm: kimpton hotels restaurants
Incident
- Discovered
- Jun 6, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Third party
- via Sabre Hospitality Solutions
- Initial access
- supply_chain
Compliance
- Time to disclose
- 7 weeks(52 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.