HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)FINANCIAL_ACCOUNTPIILowContained
Sixty Hotels
bd_fcd7b803403b6c62 · schema v1 · pii pii-v1
Full breach record for Sixty Hotels →Sixty Hotels notified California AG that unauthorized parties accessed Sabre Hospitality Solutions' SynXis CRS between Aug 10, 2016 and Mar 9, 2017. Attackers used stolen credentials to access unencrypted payment card data and reservation info. Sabre engaged forensic investigators and notified law enforcement.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-101684
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 7, 2017
- Raw hash
- 63fb1ef1db73e7f222ac85d51f84bbe37552ed42596dd44a0e8513681efb1821
Reporting entity
- Name
- Sixty Hotelsnorm: sixty hotels
Victim entity
- Name
- Sixty Hotelsnorm: sixty hotels
Incident
- Discovered
- Jun 6, 2017
- Materiality determined
- —
- Notification sent
- Mar 9, 2017
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Third party
- via Sabre Hospitality Solutions
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 13 weeks(93 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.