HYATT HOTELS CORPORATION
ent_019e5b7f1e7afb6ddec372db76c6b76a
Disclosures
12
Leak Site · State AG · 8 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
24,599
nationwide · State AG OR
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- HYATT HOTELS CORPORATION
- Normalized
- hyatt hotels— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- T27JQIMTYSH41TCD5186
- SEC EDGAR CIK
- 0001468174
- Domain
- hyatt.com
Disclosure history (12)newest first
- GLOBALLeak Siteas victim2025-12-14
Hyatt Place New York / Chelsea Hotel
- Montana State AGas victim2017-10-12
Hyatt Hotels Corporation disclosed unauthorized access to payment card information (card numbers, expiration dates, verification codes) at certain managed locations between March 18, 2017, and July 2, 2017. The incident affected a small percentage of guests who checked in during this period. Hyatt engaged third-party experts and authorities to investigate and resolved the issue.
- California State AGas victim2017-10-12
Hyatt Hotels Corporation reported unauthorized access to payment card information at certain Hyatt-managed locations between March 18, 2017, and July 2, 2017. The incident involved cardholder name, card number, expiration date, and internal verification code from cards manually entered or swiped at the front desk. Hyatt engaged third-party experts and authorities to investigate and implemented enhanced cybersecurity measures. The specific payment cards affected could not be identified.
- Massachusetts State AGas victim2017-10-12
Hyatt Hotels Corporation reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-10-12. 501 Massachusetts residents were affected. The report records the breach type as electronic.
- Oregon State AGas victim2017-10-12
Hyatt Hotels Corporation reported a data breach to the Oregon Attorney General. The breach was reported on 2017-10-12. The breach occurred during 3/18/2017 - 7/2/2017. The breach was discovered on 7/7/2017. 24,599 individuals were affected. Notice was sent on 10/12/2017.
- Washington State AGas victim2017-10-12
Hyatt Hotels Corporation notified the Washington AG of a cyberattack involving skimmers at hotel front desks. Unauthorized access to payment card data (names, numbers, CVVs) occurred between March 18 and July 2, 2017. Hyatt discovered the incident on July 7, 2017, and began notifying affected individuals, including 640 Washington residents, on October 12, 2017.
- New Hampshire State AGas victim2017-10-12
Hyatt Hotels Corporation notified the NH Attorney General of a security incident affecting 28 NH residents. Unauthorized access to payment card data (names, numbers, CVVs) occurred at certain managed/franchised locations between March 18 and July 2, 2017. Hyatt discovered suspicious activity on July 7, 2017, engaged third-party experts, and began notifying affected individuals on October 12, 2017.
- South Carolina State AGas victim2016-01-19
Hyatt Hotels Corporation disclosed a payment card incident involving malware that collected cardholder data (name, number, expiration, verification code) from onsite payment processing systems at certain locations. The unauthorized access occurred between July 30, 2015, and December 8, 2015. Hyatt engaged third-party security experts, notified law enforcement, and offered one year of fraud detection services to affected customers.
- Massachusetts State AGas victim2016-01-15
Hyatt Hotel Corporation reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2016-01-15. 9 Massachusetts residents were affected. The report records the breach type as electronic.
- Washington State AGas victim2016-01-14
Hyatt Hotels Corporation notified Washington AG of a malware incident targeting payment card data at select locations between Aug 13 and Dec 8, 2015. 15 Washington residents were identified with track 1 data exposure. Hyatt engaged third-party experts, notified law enforcement, and offered one year of credit monitoring.
- California State AGas victim2016-01-14
Hyatt Hotels Corporation disclosed a malware incident affecting payment card data at certain managed locations, primarily restaurants, between July 30, 2015, and December 8, 2015. Malware collected cardholder name, card number, expiration date, and verification code from onsite transactions. The investigation is complete, and systems have been secured. No other customer information was affected.
- Montana State AGas victim2016-01-14
Hyatt Hotels Corporation completed an investigation into a payment card incident involving malware that collected cardholder data from onsite payment processing systems at certain locations between July 30, 2015, and December 8, 2015. Hyatt engaged third-party experts, notified law enforcement and card networks, and offered one year of fraud protection services to affected customers.
Subsidiary disclosures (newest 10)filed by group companies
◈ These filings were made by or about subsidiaries of HYATT HOTELS CORPORATION — not by HYATT HOTELS CORPORATION itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- Vermont State AGvia Bunkhouse Group2025-04-15
Bunkhouse Management, LLC notified consumers that an unauthorized person viewed and/or copied files containing personal information in or around June 2024. Affected data includes names, SSNs, driver's license numbers, health insurance and medical information, financial account details, and payment card information. The company secured systems, investigated the incident, and is offering 12 months of credit monitoring.
- Maine State AGvia Bunkhouse Group2025-04-15
Bunkhouse Management, LLC reported an external system breach (hacking) occurring between June 4 and June 30, 2024. The company discovered unauthorized activity on July 17, 2024. The incident affected 5 Maine residents, exposing names, SSNs/TINs, driver's license numbers, health insurance info, medical info, financial account info, and payment card info. Notices were sent on April 15, 2025, offering 12 months of credit monitoring.
- Nebraska State AGvia Bunkhouse Group2025-04-15
Bunkhouse Management, LLC notified Nebraska residents that between June 4 and June 30, 2024, an unauthorized person viewed and/or copied files containing names, SSNs, driver's license numbers, health insurance, financial, and payment card data. The breach was discovered on July 17, 2024. Two Nebraska residents were notified on April 15, 2025. The company notified federal law enforcement and provided 12 months of credit monitoring.
- Indiana State AGvia Bunkhouse Group2025-04-15
Bunkhouse Management LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2024-06-04 and was reported on 2025-04-15. 22 Indiana residents were affected. 3,659 individuals affected in total.
- New Hampshire State AGvia Bunkhouse Group2025-04-14
Bunkhouse Management, LLC notified affected individuals of unauthorized system activity in or around June 2024 where an unauthorized person viewed and/or copied files containing personal information. The company secured systems, investigated, and offered credit monitoring services.
- Massachusetts State AGvia Bunkhouse Group2024-08-28
Bunkhouse Management, LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-08-28. 8 Massachusetts residents were affected.
- GLOBALLeak Sitevia Bunkhouse Group2024-07-24
Bunkhouse Group is a company that operates in the Lodging & Resorts industry.
- GLOBALLeak Sitevia Bunkhouse Group2024-06-01
Bunkhouse Group is a company that operates in the Lodging & Resorts industry.
- GLOBALPressvia Bunkhouse Group2024-06-01
Data Breach Notification. Bunkhouse Management, LLC: In June 2024, Bunkhouse Management, LLC discovered unauthorized activity on its systems, during which an individual accessed and copied files containing personal data. The exposed information included names, Social Security or taxpayer identification numbers, driver’s license numbers, health and medical information, financial account data, and payment card details. Bunkhouse secured its systems, conducted a thorough investigation, and is offering twelve months of free credit monitoring and identity theft protection to affected individuals. The cyberattack was claimed by bianlian on 2024-07-24. Linked ransomware group: bianlian.
- Massachusetts State AGvia Bunkhouse Group2022-11-02
Bunkhouse Management, LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-11-02. 2 Massachusetts residents were affected. The report records the breach type as electronic.