HYATT HOTELS CORPORATION
ent_019e5b7f1e7afb6ddec372db76c6b76a
Disclosures
7
State AG · 4 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
24,599
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- HYATT HOTELS CORPORATION
- Normalized
- hyatt hotels— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- T27JQIMTYSH41TCD5186
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (7)newest first
- 🦬Montana State AGas victim2017-10-12
Hyatt Hotels reported a data breach to the Montana Attorney General. The breach was reported on 2017-10-12. The breach occurred from 3/18/2017 to 7/2/2017. 14 Montana residents were affected.
- 🐻California State AGas victim2017-10-12
Hyatt Hotels Corporation reported unauthorized access to payment card information (cardholder name, number, expiration, verification code) from cards manually entered or swiped at front desks of certain Hyatt-managed locations between March 18, 2017 and July 2, 2017. The incident affected a small percentage of payment cards used by guests during the at-risk period. Hyatt engaged third-party experts, payment card networks, and authorities, and implemented enhanced cybersecurity measures.
- 🦫Oregon State AGas victim2017-10-12
Hyatt Hotels Corporation reported a data breach to the Oregon Attorney General. The breach was reported on 2017-10-12. The breach occurred during 3/18/2017 - 7/2/2017. The breach was discovered on 7/7/2017. 24,599 individuals were affected. Notice was sent on 10/12/2017.
- 🌲Washington State AGas victim2017-10-12
Hyatt Hotels Corporation, a business sector entity reported a skimmers incident to the Washington Attorney General. The organization became aware of the incident on 2017-07-07 and filed notice on 2017-10-12. 640 Washington residents were affected. 97 days elapsed between awareness and notification. 111 days to identify the breach. 0 days to contain the breach.
- 🌲Washington State AGas victim2016-01-14
Hyatt Hotels Corporation, a business sector entity reported a malware incident to the Washington Attorney General. The organization became aware of the incident on 2015-11-24 and filed notice on 2016-01-14. 15 Washington residents were affected. 51 days elapsed between awareness and notification. 103 days to identify the breach. 14 days to contain the breach.
- 🐻California State AGas victim2016-01-14
Hyatt Hotels Corporation disclosed a payment card incident involving malware deployed at certain managed locations (primarily restaurants) between July 30, 2015, and December 8, 2015. The malware collected payment card data (cardholder name, number, expiration, verification code). Hyatt engaged third-party security experts, notified law enforcement and payment networks, and offered one year of fraud protection services to affected customers. No other customer information was affected.
- 🦬Montana State AGas victim2016-01-14
Hyatt Hotels Corporation reported a data breach to the Montana Attorney General. The breach was reported on 2016-01-14. The breach occurred from 7/30/2015 to 12/8/2015. 1 Montana residents were affected.
Subsidiary disclosures (7)filed by group companies
◈ These filings were made by or about subsidiaries of HYATT HOTELS CORPORATION — not by HYATT HOTELS CORPORATION itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- 🦞Maine State AGvia Bunkhouse Management2025-04-15
Bunkhouse Management, LLC reported a data breach to the Maine Attorney General affecting 5 state residents. The breach, described as an external system breach or hacking, occurred on June 30, 2024, and was discovered on April 9, 2025. Affected individuals were notified in writing on April 15, 2025. The company offered 12 months of identity theft protection services through Cyberscout from TransUnion.
- 🌲Washington State AGvia Two Roads Hospitality2017-08-03
Two Roads Hospitality, LLC, a business sector entity reported a malware incident to the Washington Attorney General. The organization became aware of the incident on 2017-06-06 and filed notice on 2017-08-03. 5,401 Washington residents were affected. 58 days elapsed between awareness and notification. 300 days to identify the breach. 0 days to contain the breach.
- 🦬Montana State AGvia Standard International Management2017-07-21
Standard International Management reported a data breach to the Montana Attorney General. The breach was reported on 2017-07-21. The breach occurred from 8/10/2016 to 3/9/2017. 16 Montana residents were affected.
- 🐻California State AGvia Standard International Management2017-07-21
Standard International Management LLC reported a data breach involving its third-party provider, Sabre Hospitality Solutions. Unauthorized access to Sabre's SynXis Central Reservations System occurred between August 10, 2016, and March 9, 2017. The incident exposed payment card details (names, numbers, expiration dates, potential CVVs) and guest PII (names, emails, phones, addresses) for a subset of hotel reservations. Sabre engaged forensic investigators and notified law enforcement and payment brands. No Social Security or government IDs were accessed.
- 🦬Montana State AGvia Two Roads Hospitality2017-07-14
Two Roads Hospitality reported a data breach to the Montana Attorney General. The breach was reported on 2017-07-14. The breach occurred from 8/10/2016 to 3/9/2017. 165 Montana residents were affected.
- 🦫Oregon State AGvia Two Roads Hospitality2017-07-14
Two Roads Hospitality, LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2017-07-14. The breach occurred during 8/10/2016 - 3/9/2017. The breach was discovered on 6/6/2017. 92,000 individuals were affected. Notice was sent on 7/14/2017.
- 🦬Montana State AGvia Miraval Arizona Resort and Spa2017-06-29
Miraval Arizona Resort and Spa reported a data breach to the Montana Attorney General. The breach was reported on 2017-06-29. The breach occurred from 8/10/2016 to 3/9/2017. 3 Montana residents were affected.