Resort Data Processing
ent_64bb1292d5e7cd6aa8e1005a
Disclosures
19
State AG · 8 jurisdictions
Incidents
3
filings grouped by incident
Max affected reported
61,500
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Resort Data Processing
- Normalized
- resort data processing— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- resortdata.com
Disclosure history (19)newest first
- 🦀Maryland State AGas victim2026-04-23
Resort Data Processing (RDP) disclosed a security event where an unauthorized actor used compromised vendor credentials to scrape customer reservation data, including names, payment card numbers, CVVs, and expiration dates. The incident occurred between December 25, 2024, and January 22, 2025. RDP engaged forensic investigators, offered one year of credit monitoring via Kroll, and implemented additional system safeguards.
- 🏎️Indiana State AGas victim2025-05-14
Resort Data Processing reported a data breach to the Indiana Attorney General. The breach occurred on 2025-02-19 and was reported on 2025-05-14. 32 Indiana residents were affected. 5,004 individuals affected in total.
- ⛰️New Hampshire State AGas victim2025-05-14
Resort Data Processing notified the NH AG of a security event where an unauthorized actor injected a malicious script on customer websites to scrape reservation data between Feb 19 and Apr 17, 2025. 35 NH residents were affected. RDP engaged forensic investigators, stopped the script, and offered 24 months of credit monitoring via TransUnion.
- 🦞Maine State AGas victim2025-05-14
Resort Data Processing reported an external system breach that occurred between February 19, 2025, and April 17, 2025. The breach was discovered on April 23, 2025. The incident affected 44 Maine residents, who were notified on May 14, 2025. The company offered 12 months of credit monitoring services through TransUnion to those affected.
- 🦫Oregon State AGas victim2025-05-14
Resort Data Processing reported a data breach to the Oregon Attorney General. The breach was reported on 2025-05-14. The breach occurred during 2/19/2025 - 4/17/2025. The breach was discovered on 4/23/2025. 5,007 individuals were affected. Notice was sent on 5/14/2025.
- ⛰️New Hampshire State AGas victim2025-03-21
Resort Data Processing (RDP) notified New Hampshire of a security event where an unauthorized actor used compromised vendor credentials to scrape personal information from individuals making internet reservations at a customer location. RDP engaged forensic investigators and is offering one year of credit monitoring and identity restoration services.
- 🏎️Indiana State AGas victim2025-03-20
Resort Data Processing reported a data breach to the Indiana Attorney General. The breach occurred on 2024-12-25 and was reported on 2025-03-20. 111 Indiana residents were affected. 6,556 individuals affected in total.
- 🦬Montana State AGas victim2023-10-27
Resort Data Processing, Inc reported a data breach to the Montana Attorney General. The breach was reported on 2023-10-27. The breach occurred from 8/21/2023 to 8/23/2023. 73 Montana residents were affected.
- 🦞Maine State AGas victim2023-10-27
Resort Data Processing, Inc. experienced an external system breach where an unauthorized party accessed customer names and financial account information, including credit/debit card numbers and their associated security codes, access codes, passwords, or PINs. The breach occurred on August 1, 2022, was discovered on August 21, 2023, and affected 85 Maine residents. The company offered 12 months of credit monitoring and identity restoration services through Kroll Inc.
- 🐻California State AGas victim2023-10-27
Resort Data Processing, Inc. (RDP) disclosed that an unauthorized actor exploited a vulnerability in its reservation booking application to download payment card information (card numbers, expiration dates, CVVs) and names. The breach occurred between August 2022 and mid-August 2023. RDP identified the issue on September 22, 2023, and subsequently issued software updates to remediate the vulnerability. A forensic firm was engaged, and law enforcement was notified. RDP is offering one year of complimentary identity monitoring services through Kroll to affected individuals.
- ⛰️New Hampshire State AGas victim2023-10-27
Resort Data Processing, Inc. (RDP) notified the New Hampshire Attorney General on October 27, 2023, of a security incident affecting 271 state residents. Discovered on August 21, 2023, an unauthorized actor exploited a SQL injection vulnerability in clients' Internet Reservation Modules to exfiltrate payment card information. RDP contained the activity on August 23, 2023, patched the vulnerability, engaged forensic investigators, and notified law enforcement. Affected individuals were offered one year of credit monitoring.
- 🦫Oregon State AGas victim2023-10-27
Resort Data Processing, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-10-27. The breach occurred during 8/1/2022 - 8/23/2023. The breach was discovered on 8/21/2023. 61,500 individuals were affected. Notice was sent on 10/27/2023.
- 🌲Washington State AGas victim2023-10-27
Resort Data Processing, Inc., a business sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2023-08-21 and filed notice on 2023-10-27. 2,319 Washington residents were affected. 67 days elapsed between awareness and notification. 385 days to identify the breach. 2 days to contain the breach.
- 🦬Montana State AGas victim2021-07-27
Resort Data Processing, Inc. reported a data breach to the Montana Attorney General. The breach was reported on 2021-07-27. The breach occurred from 2/22/2021 to 6/14/2021. 37 Montana residents were affected.
- 🦬Montana State AGas victim2021-07-23
Resort Data Processing, Inc. reported a data breach to the Montana Attorney General. The breach was reported on 2021-07-23. The breach occurred from 2/22/2021 to 6/14/2021. 37 Montana residents were affected.
- 🦫Oregon State AGas victim2021-07-22
Resort Data Processing, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2021-07-22. The breach occurred during 1/1/0001. The breach was discovered on 6/14/2021. 10,210 individuals were affected. Notice was sent on 7/23/2021.
- 🐻California State AGas victim2021-07-22
Resort Data Processing, Inc., a property management software provider, disclosed a cybersecurity attack on its online booking system used by hotels and resorts. Suspicious activity was detected on June 14, 2021, involving malicious code that acquired credit/debit card information and customer PII (name, address, email) from reservations made between January 2019 and June 2021. The company terminated attacker access, deployed a security patch, and engaged forensic investigators.
- 🦞Maine State AGas victim2021-07-14
Resort Data Processing, Inc. reported a cybersecurity incident occurring between February 22, 2021, and June 14, 2021. The breach involved unauthorized access by hackers using malicious code, resulting in the exposure of names and financial account numbers (including credit/debit card numbers with security codes/PINs). A total of 9,790 individuals were affected, including 148 Maine residents. Written notification was sent to consumers on July 14, 2021. No identity theft protection services were offered.
- 🌲Washington State AGas victim2021-07-14
Resort Data Processing, Inc., a business sector entity reported a malware incident to the Washington Attorney General. The organization became aware of the incident on 2021-06-14 and filed notice on 2021-07-14. 1,669 Washington residents were affected. 30 days elapsed between awareness and notification. 112 days to identify the breach. 0 days to contain the breach.