DisclosureLens
HackingHospitalityHospitalitySupply Chain (3P Vendor)Customer Data InvolvedFinancial accountFinancial credentialsIdentity (basic)LowContained

Kimpton Hotels & Restaurants

bd_f9071946d36b9e1a · schema v1 · pii pii-v1

Severity

Low

Discovered

Jun 6, 2017

Filed

Jul 28, 2017

To disclose

7 weeks

Affected

Not disclosed

Linked

4 filings

Confidence

64%
Full breach record for Kimpton Hotels & Restaurants2 incidents on file

Kimpton Hotels & Restaurants notified customers of a data security incident involving its third-party reservation vendor, Sabre Hospitality Solutions. Unauthorized access to Sabre's SynXis Central Reservations system occurred between August 10, 2016, and March 9, 2017. Kimpton was notified by Sabre on June 6, 2017. The incident may have exposed payment card information (card numbers, expiration dates, security codes) and basic identity information (names, email addresses, phone numbers, mailing addresses) for hotel reservations. The breach did not affect Kimpton's own systems. Kimpton confirmed Sabre engaged forensic investigators and notified law enforcement and payment card brands.

California clockDiscovered Jun 6, 2017Notified Jul 11, 201735d CA 60-day OK7 weeks discovery → filing

Incident timeline

undetected · 300 days
discovery → filing · 7 weeks / 52 days

Aug 10, 2016

Begins

Jun 6, 2017

Discovered

Jul 28, 2017

Filed

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 4 states

View merged incident ↗
New Hampshire State AGJul 28 · first
Montana State AGJul 28 · first
Massachusetts State AGJul 28 · first
California State AGJul 28 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.