Rosen Hotels & Resorts
ent_8fc193fa19287e6d28bcb287
Disclosures
4
State AG · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
268
as filed · State AG MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Rosen Hotels & Resorts
- Normalized
- rosen hotels resorts— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- rosenhotels.com
Disclosure history (4)newest first
- Massachusetts State AGas victim2016-03-08
Rosen Hotels & Resorts Inc reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2016-03-08. 268 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2016-03-04
Rosen Hotels & Resorts disclosed a payment card incident where malware installed in its payment card network captured magnetic stripe data (card numbers, names, expiration dates) from guests who stayed between Sept 2, 2014, and Feb 18, 2016. The company detected unauthorized charges on Feb 3, 2016, hired a cybersecurity firm, and notified affected guests via letter/email on March 4, 2016.
- California State AGas victim2016-03-04
Rosen Hotels & Resorts disclosed a payment card data breach affecting guests who used cards between September 2, 2014, and February 18, 2016. Malware installed on the payment network captured magnetic stripe data, including card numbers, expiration dates, and verification codes. The incident was discovered on February 3, 2016, after reports of unauthorized charges. The company engaged forensic experts, contained the incident, and implemented enhanced security measures.
- New Hampshire State AGas victim2016-03-04
Rosen Hotels & Resorts Inc. notified the NH Attorney General of a payment card malware incident. Malware installed in the card network stole cardholder name, number, expiration, and verification codes from guests who stayed between Sept 2, 2014 and Feb 18, 2016. Notifications were sent March 4, 2016. No specific count of affected individuals was disclosed in this filing.