Four Seasons Hotels Limited
ent_69451aefc6cfdf164e2d14d2
Disclosures
5
State AG · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
636
as filed · State AG WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Four Seasons Hotels Limited
- Normalized
- four seasons hotels— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- Montana State AGas victim2017-07-07
Four Seasons Hotels notified Montana residents of a data security incident involving Sabre Hospitality Solutions SynXis Centre Reservations System. Unauthorized access to payment card and reservation data occurred between August 2016 and March 2017 via compromised credentials. Sabre contained the breach and engaged forensic investigators.
- Massachusetts State AGas victim2017-07-07
Four Seasons Hotels Limited reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-07-07. 622 Massachusetts residents were affected. The report records the breach type as electronic.
- Washington State AGas victim2017-07-06
Four Seasons Hotels Limited notified the Washington AG of a third-party breach involving Sabre Hospitality Solutions. Unauthorized access to Sabre's SynXis CRS system occurred from Aug 10, 2016 to Mar 9, 2017 via stolen credentials. 636 Washington residents affected; payment card info and PII exposed. Incident contained June 6, 2017.
- California State AGas victim2017-07-06
Four Seasons Hotels Limited notified California residents of a data breach involving its third-party reservation provider, Sabre. An unauthorized party obtained account credentials to Sabre's central reservations system, accessing unencrypted payment card information (cardholder name, number, expiration date, and potentially security code) and basic identity information (name, email, phone, address) for a subset of reservations. The unauthorized access occurred between August 10, 2016, and March 9, 2017. Four Seasons was notified on June 6, 2017. Sabre contained the incident, revoked access, and engaged cybersecurity experts. No evidence of data exfiltration was found, but it remains a possibility. Reservations made directly with Four Seasons were not affected.
- New Hampshire State AGas victim2017-07-06
Sabre Hospitality Solutions experienced a data breach affecting 19 New Hampshire residents. Unauthorized access via stolen credentials exposed payment card info and guest PII between Aug 2016 and Mar 2017. Incident contained; investigation ongoing.