Resort Data Processing
ent_64bb1292d5e7cd6aa8e1005a
Disclosures
25+
State AG · 11 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
61,500
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Resort Data Processing
- Normalized
- resort data processing— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- resortdata.com
Disclosure history (newest 25)newest first
- Maryland State AGas victim2026-04-23
Resort Data Processing (RDP) disclosed a security event where an unauthorized actor used compromised vendor credentials to scrape customer reservation data, including names, payment card numbers, CVVs, and expiration dates. The incident occurred between December 25, 2024, and January 22, 2025. RDP engaged forensic investigators, offered one year of credit monitoring via Kroll, and implemented additional system safeguards.
- Massachusetts State AGas victim2025-05-15
Resort Data Processing reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-05-15. 95 Massachusetts residents were affected.
- Indiana State AGas victim2025-05-14
Resort Data Processing reported a data breach to the Indiana Attorney General. The breach occurred on 2025-02-19 and was reported on 2025-05-14. 32 Indiana residents were affected. 5,004 individuals affected in total.
- New Hampshire State AGas victim2025-05-14
Resort Data Processing notified the NH AG of a security event where an unauthorized actor injected a malicious script on customer websites to scrape reservation data between Feb 19 and Apr 17, 2025. 35 NH residents were affected. RDP engaged forensic investigators, stopped the script, and offered 24 months of credit monitoring via TransUnion.
- Maine State AGas victim2025-05-14
Resort Data Processing (RDP) disclosed an external system breach where an unauthorized actor injected a malicious script to scrape customer reservation data, including names, payment card numbers, CVVs, and expiration dates. The incident affected 5,007 individuals, including 44 Maine residents, between February 19 and April 17, 2025. RDP engaged forensic investigators and offered 12 months of TransUnion credit monitoring.
- Oregon State AGas victim2025-05-14
Resort Data Processing reported a data breach to the Oregon Attorney General. The breach was reported on 2025-05-14. The breach occurred during 2/19/2025 - 4/17/2025. The breach was discovered on 4/23/2025. 5,007 individuals were affected. Notice was sent on 5/14/2025.
- Nebraska State AGas victim2025-05-14
Resort Data Processing (RDP) notified Nebraska AG of a security event where an unauthorized actor injected a malicious script on a customer website to scrape reservation data. The incident occurred between March 5 and April 7, 2025. Affected data included names, payment card numbers (ending in [X]), CVVs, and expiration dates. RDP engaged forensic investigators, offered one year of credit monitoring via TransUnion, and deployed additional system safeguards.
- Massachusetts State AGas victim2025-03-21
Resort Data Processing reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-03-21. 1 Massachusetts residents were affected.
- New Hampshire State AGas victim2025-03-21
Resort Data Processing (RDP) notified New Hampshire of a security event where an unauthorized actor used compromised vendor credentials to scrape personal information from individuals making internet reservations at a customer location. RDP engaged forensic investigators and is offering one year of credit monitoring and identity restoration services.
- Nebraska State AGas victim2025-03-20
Resort Data Processing, a general business entity filed a data breach notification with the Nebraska Attorney General. The breach was discovered on 2025-01-28 according to the AG's register. The breach is dated 2024-12-24. Nebraska residents were notified on 2025-03-20.
- Indiana State AGas victim2025-03-20
Resort Data Processing reported a data breach to the Indiana Attorney General. The breach occurred on 2024-12-25 and was reported on 2025-03-20. 111 Indiana residents were affected. 6,556 individuals affected in total.
- Montana State AGas victim2023-10-27
Resort Data Processing, Inc. notified Montana residents of a data breach where an unauthorized actor exploited a vulnerability in its reservation booking application to download payment card information (including CVV) between August 2022 and mid-August 2023. RDP determined the breach on September 22, 2023, engaged forensic investigators, notified law enforcement, and offered one year of identity monitoring via Kroll.
- Maine State AGas victim2023-10-27
Resort Data Processing, Inc. experienced an external system breach where an unauthorized party accessed customer names and financial account information, including credit/debit card numbers and their associated security codes, access codes, passwords, or PINs. The breach occurred on August 1, 2022, was discovered on August 21, 2023, and affected 85 Maine residents. The company offered 12 months of credit monitoring and identity restoration services through Kroll Inc.
- California State AGas victim2023-10-27
Resort Data Processing, Inc. (RDP) disclosed that an unauthorized actor exploited a vulnerability in its reservation booking application to download payment card information (card numbers, expiration dates, CVVs) and names. The breach occurred between August 2022 and mid-August 2023. RDP identified the issue on September 22, 2023, and subsequently issued software updates to remediate the vulnerability. A forensic firm was engaged, and law enforcement was notified. RDP is offering one year of complimentary identity monitoring services through Kroll to affected individuals.
- Indiana State AGas victim2023-10-27
Resort Data Processing, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2022-08-01 and was reported on 2023-10-27. 536 Indiana residents were affected. 61,500 individuals affected in total.
- New Hampshire State AGas victim2023-10-27
Resort Data Processing, Inc. (RDP) notified the New Hampshire Attorney General on October 27, 2023, of a security incident affecting 271 state residents. Discovered on August 21, 2023, an unauthorized actor exploited a SQL injection vulnerability in clients' Internet Reservation Modules to exfiltrate payment card information. RDP contained the activity on August 23, 2023, patched the vulnerability, engaged forensic investigators, and notified law enforcement. Affected individuals were offered one year of credit monitoring.
- Massachusetts State AGas victim2023-10-27
Resort Data Processing, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-10-27. 1,279 Massachusetts residents were affected. The report records the breach type as electronic.
- Oregon State AGas victim2023-10-27
Resort Data Processing, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-10-27. The breach occurred during 8/1/2022 - 8/23/2023. The breach was discovered on 8/21/2023. 61,500 individuals were affected. Notice was sent on 10/27/2023.
- Washington State AGas victim2023-10-27
Resort Data Processing, Inc. notified Washington AG of a security incident affecting 2,319 state residents. Unauthorized actors exploited a SQL injection vulnerability in clients' reservation systems between August 2022 and August 2023 to exfiltrate names, addresses, and credit card data. RDP contained the breach on August 23, 2023, and offered credit monitoring.
- Illinois State AGas victim2023-01-01
RESORT DATA PROCESSING, INC. filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-746). The register records the breach as discovered on August 21, 2023. Additional entities named: WILDERNESS HOTEL & GOLF RESORT. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Montana State AGas victim2021-07-27
Resort Data Processing, Inc. notified Montana AG of a cybersecurity attack on its online booking system. Malicious activity occurred from Jan 2019 to June 2021. Attackers used malicious code to acquire credit/debit card info. Disclosed June 14, 2021. Notices sent July 23, 2021. Forensic firm engaged; patch deployed.
- Montana State AGas victim2021-07-23
Resort Data Processing, Inc. notified affected individuals of a cybersecurity attack on its online booking system. Attackers exploited a vulnerability to exfiltrate payment card information and PII from reservations made between Jan 2019 and June 2021. The company engaged forensic investigators, deployed a patch, and enhanced security controls.
- Massachusetts State AGas victim2021-07-23
Resort Data Processing, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-07-23. 213 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2021-07-23
Resort Data Processing, Inc. notified customers of a cybersecurity attack on its online booking system. Attackers used malicious code to acquire credit/debit card info and PII from reservations made between Jan 2019 and June 2021. The company terminated access, deployed a patch, and engaged forensic investigators.
- Oregon State AGas victim2021-07-22
Resort Data Processing, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2021-07-22. The breach occurred during 1/1/0001. The breach was discovered on 6/14/2021. 10,210 individuals were affected. Notice was sent on 7/23/2021.