HackingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTPIIMediumContained
Hudson River Partners I L.P.
bd_fed038a81b8b76ac · schema v1 · pii pii-v1
Full breach record for Hudson River Partners I L.P. →The Historic Thayer Hotel experienced unauthorized access to its computer systems on September 19, 2025. The incident exposed personal information including names combined with driver's license numbers, passport numbers, dates of birth, and state ID numbers. A small number of individuals may have had Social Security numbers impacted. The hotel engaged third-party forensic specialists, notified law enforcement, and is offering 12 months of credit monitoring through Kroll Security to affected individuals.
Vermont clock⏱ VT AG >14 bday6 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_12aa427de683d475California State AGfiled 2025-11-03Verified
- bd_5ff7442183fae9c4Indiana State AGfiled 2025-11-03Verified
- bd_7e2139f3f98129d0Maine State AGfiled 2025-11-03Verified
- bd_d48218c6d02db346Texas State AGfiled 2025-11-04(1d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 3d gap
- bd_21fe280fdcbdc5b0New Hampshire State AGfiled 2025-11-05(2d gap)Verified
- bd_8009cd56be9477b8Montana State AGfiled 2025-10-31(3d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-11-03-hudson-river-partners-i-dba-thayer-hotel-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 3, 2025
- Raw hash
- 3882f60fd043b651f6e75c59e79cd02d4da67636ca8d94153987c0a36fae7484
Reporting entity
- Name
- Hudson River Partners I L.P.norm: hudson river partners i
- Domain
- thethayerhotel.com
Victim entity
- Name
- Hudson River Partners I L.P.norm: hudson river partners i
- Domain
- thethayerhotel.com
Incident
- Discovered
- Sep 19, 2025
- Materiality determined
- Oct 31, 2025
- Notification sent
- Oct 31, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notifying appropriate regulators
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(45 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.