Red Roof Inns
ent_253ae6e843e2d64347a50ad3
Disclosures
7
State AG · 6 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
27,327
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Red Roof Inns
- Normalized
- red roof inns— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (7)newest first
- Massachusetts State AGas victim2023-12-08
Red Roof Inns, Inc reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-12-08. 796 Massachusetts residents were affected. The report records the breach type as electronic.
- Vermont State AGas victim2023-12-08
Red Roof experienced a ransomware attack on September 23, 2023, where an unauthorized actor gained access to systems, encrypted data, and exfiltrated a limited amount of information including names and other personal data. The company contained the incident, reset passwords, and engaged forensic experts. Affected individuals are offered 24 months of credit monitoring.
- Maine State AGas victim2023-12-08
Red Roof Inns, Inc. reported an external system breach that occurred between September 21, 2023, and September 23, 2023. The breach was discovered on September 23, 2023. The incident affected 11 Maine residents, part of a larger group of 27,327 individuals. The compromised data included names combined with financial account or credit/debit card numbers and their associated security codes or PINs. Red Roof Inns began notifying affected individuals on December 8, 2023, and offered 24 months of identity theft protection and credit monitoring services through IDX.
- Montana State AGas victim2023-12-08
Red Roof experienced a ransomware attack on September 23, 2023, resulting in the encryption of a limited subset of data and the copying of a limited amount of data. The incident involved personal information (names, etc.). Red Roof took systems offline, reset passwords, engaged cybersecurity experts, and reported to law enforcement. Affected individuals were offered 24 months of credit monitoring.
- Illinois State AGas victim2023-01-01
RED ROOF INNS, INC. filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-831). The register records the breach as discovered on September 23, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Montana State AGas victim2017-08-29
Red Roof Inns notified customers that a third-party vendor, Sabre Hospitality Solutions (SHS), experienced unauthorized access to a database containing reservation data. The incident, discovered on June 6, 2017, involved access occurring on August 10, 2016. Affected data included names, addresses, and payment card details for individuals who booked rooms via third-party sites.
- New Hampshire State AGas victim2017-08-29
Red Roof Inns reported a data breach involving its third-party vendor Sabre Hospitality Solutions (SHS). Unauthorized access occurred on August 10, 2016, discovered by SHS on June 6, 2017. The incident exposed customer names, addresses, emails, phone numbers, and credit/debit card details (including CVV). 25 New Hampshire residents were notified on August 28, 2017. Law enforcement was contacted.