Hard Rock Hotel & Casino Las Vegas
ent_7244f13e519acf4bc1116f2e
Disclosures
9
State AG · 6 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
173,000
as filed · State AG NH
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Hard Rock Hotel & Casino Las Vegas
- Normalized
- hard rock hotel casino las vegas— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (9)newest first
- South Carolina State AGas victim2016-06-28
Hard Rock Hotel & Casino Las Vegas notified customers of a payment card incident involving card scraping malware. Unauthorized access occurred between Oct 27, 2015 and Mar 21, 2016. The resort engaged a cyber-security firm, notified law enforcement, and worked with payment card networks. Data exposed included cardholder names, numbers, expiration dates, and verification codes. No specific count of affected individuals was provided.
- California State AGas victim2016-06-27
Hard Rock Hotel & Casino Las Vegas experienced a payment card data breach caused by card scraping malware installed on point-of-sale systems. The malware targeted payment card data (cardholder name, card number, expiration date, and internal verification code) at certain restaurant and retail outlets between October 27, 2015, and March 21, 2016. The incident was discovered on May 13, 2016, after reports of fraudulent activity. The company engaged a cybersecurity firm, notified law enforcement, and worked with payment card networks to monitor affected cards.
- Washington State AGas victim2016-06-27
Hard Rock Hotel & Casino Las Vegas notified Washington AG of a malware incident involving payment card data. Unauthorized access occurred between Oct 27, 2015 and Mar 21, 2016. Malware scraped card data including names, numbers, and verification codes. Discovered May 13, 2016. No specific count of affected individuals available; notification provided via website/press release.
- Oregon State AGas victim2016-06-27
Hard Rock Hotel & Casino Las Vegas reported a data breach to the Oregon Attorney General. The breach was reported on 2016-06-27. The breach occurred during 10/27/2015. The breach was discovered on 5/13/2016. 1 individuals were affected. Notice was sent on 6/27/2016.
- New Hampshire State AGas victim2016-06-27
Hard Rock Hotel & Casino Las Vegas notified the NH Attorney General of a payment card incident involving card scraping malware. Unauthorized access occurred between Oct 27, 2015 and Mar 21, 2016. The resort engaged forensic investigators, reset passwords, and deployed encryption/tokenization. Exact affected count unknown due to lack of customer contact info.
- Montana State AGas victim2016-06-27
Hard Rock Hotel & Casino Las Vegas notified customers of a payment card incident involving card scraping malware. Unauthorized access occurred between Oct 27, 2015 and Mar 21, 2016. Data included card numbers, names, and verification codes. The resort engaged a cyber-security firm and notified law enforcement.
- South Carolina State AGas victim2015-05-04
Hard Rock Hotel & Casino Las Vegas notified customers of a security incident where criminal hackers accessed credit/debit card data (names, numbers, CVVs) from transactions between Sept 3, 2014 and April 2, 2015 at retail locations. Notices were sent May 1, 2015. Experian was engaged for one-year identity protection.
- New Hampshire State AGas victim2015-04-30
Hard Rock Hotel & Casino Las Vegas notified NH AG of a payment card security incident. Malware on a POS server allowed theft of card numbers, names, and CVVs from Sept 3, 2014 to April 2, 2015. Approx 173,000 cards affected. FBI notified. One year of Experian identity protection offered.
- California State AGas victim2015-04-30
Hard Rock Hotel & Casino Las Vegas notified customers of a security incident involving criminal hackers who accessed credit/debit card information (names, card numbers, CVV codes) at retail and service locations between September 3, 2014, and April 2, 2015. The attack did not affect hotel, casino, or specific partner restaurant transactions. The company offered one year of complimentary identity protection through Experian.