Preferred Hotel Group
ent_72e21123695e7eabf3e3e7a1
Disclosures
7
State AG · 4 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
21,687
as filed · State AG WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Preferred Hotel Group
- Normalized
- preferred hotel— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (7)newest first
- 🌲Washington State AGas victim2018-03-02
Preferred Hotels & Resorts, a business sector entity reported a malware incident to the Washington Attorney General. The organization became aware of the incident on 2018-02-14 and filed notice on 2018-03-02. 21,687 Washington residents were affected. 16 days elapsed between awareness and notification. 623 days to identify the breach. 0 days to contain the breach.
- 🦫Oregon State AGas victim2018-03-02
Preferred Hotel & Resorts reported a data breach to the Oregon Attorney General. The breach was reported on 2018-03-02. The breach occurred during 6/1/2018 - 11/1/2017. The breach was discovered on 1/25/2018. 9,182 individuals were affected. Notice was sent on 3/5/2018.
- 🐻California State AGas victim2018-03-02
Preferred Hotels & Resorts disclosed a data breach involving its third-party service provider, Sabre Hospitality Solutions. An unauthorized party gained access to Sabre's SynXis Central Reservations System using valid user credentials between June 2016 and November 2017. The incident exposed payment card information (card numbers, expiration dates, CVVs) and guest PII (names, emails, phone numbers, addresses) for a subset of reservations. No Preferred network systems were directly compromised. Sabre enhanced security controls and notified law enforcement and payment card brands.
- 🐻California State AGas victim2017-07-14
Preferred Hotel Group, Inc. reported a data breach involving its third-party provider, Sabre Hospitality Solutions. Unauthorized access occurred between August 10, 2016, and March 9, 2017, affecting a subset of hotel reservations. The breach exposed unencrypted payment card information (cardholder name, number, expiration, potential security code) and guest PII (name, email, phone, address). No SSN, passport, or driver's license data was accessed. The incident was discovered on June 6, 2017, following Sabre's forensic investigation. Response actions included notifying law enforcement, payment card brands, and credit reporting agencies, and working with Sabre to improve security processes.
- 🦫Oregon State AGas victim2017-07-07
Preferred Hotel Group, Inc reported a data breach to the Oregon Attorney General. The breach was reported on 2017-07-07. The breach occurred during 8/10/2016 - 3/9/2017.
- 🦬Montana State AGas victim2017-07-06
Preferred Hotel Group reported a data breach to the Montana Attorney General. The breach was reported on 2017-07-06. The breach occurred from 8/10/2016 to 3/9/2017. 500 Montana residents were affected.
- 🌲Washington State AGas victim2017-06-30
Preferred Hotel Group, a business sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2017-06-06 and filed notice on 2017-06-30. 2,370 Washington residents were affected. 24 days elapsed between awareness and notification. 300 days to identify the breach. 0 days to contain the breach.