Kimpton Hotels & Restaurants
ent_becf66b06d2d353f522e27ec
Disclosures
13
State AG · 7 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
5,584
as filed · State AG MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Kimpton Hotels & Restaurants
- Normalized
- kimpton hotels restaurants— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (13)newest first
- New Hampshire State AGas victim2017-07-28
Kimpton Hotels & Restaurants notified the NH AG of a data security incident involving its third-party reservation vendor, Sabre. Unauthorized access to payment card info (names, card numbers, CVVs) and PII occurred between Aug 2016 and Mar 2017. Kimpton learned of the incident on June 6, 2017. Approximately 88 NH residents were affected. Sabre engaged forensic investigators and notified law enforcement.
- Montana State AGas victim2017-07-28
Kimpton Hotels & Restaurants notified customers of a third-party data breach involving Sabre Hospitality Solutions. Unauthorized access to reservation systems occurred between August 2016 and March 2017, exposing payment card details and personal information. Kimpton confirmed Sabre's investigation and notified law enforcement.
- Massachusetts State AGas victim2017-07-28
Kimpton Hotels & Restaurants reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-07-28. 910 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2017-07-28
Kimpton Hotels & Restaurants notified customers of a data security incident involving its third-party reservation vendor, Sabre Hospitality Solutions. Unauthorized access to Sabre's SynXis Central Reservations system occurred between August 10, 2016, and March 9, 2017. Kimpton was notified by Sabre on June 6, 2017. The incident may have exposed payment card information (card numbers, expiration dates, security codes) and basic identity information (names, email addresses, phone numbers, mailing addresses) for hotel reservations. The breach did not affect Kimpton's own systems. Kimpton confirmed Sabre engaged forensic investigators and notified law enforcement and payment card brands.
- New Hampshire State AGas victim2016-09-16
Kimpton Hotels & Restaurants notified the New Hampshire Attorney General of a payment card incident affecting residents who used cards at affected locations between Feb 16 and July 7, 2016. The company mailed substitute notifications to 689 identified NH residents starting Sept 9, 2016.
- Massachusetts State AGas victim2016-09-06
Kimpton Hotels & Restaurants reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2016-09-06. 5,584 Massachusetts residents were affected. The report records the breach type as electronic.
- South Carolina State AGas victim2016-09-01
Kimpton Hotels & Restaurants notified South Carolina residents of a malware incident affecting payment card processing servers at the Hotel Lumen. Unauthorized charges were reported on July 15, 2016. Malware captured track data (card numbers, expiration dates, verification codes) from February 16 to July 7, 2016. The incident was resolved, law enforcement was notified, and forensic firms were engaged.
- New Hampshire State AGas victim2016-08-31
Kimpton Hotels & Restaurants notified NH AG of a security incident involving payment card malware. Unauthorized charges reported July 15, 2016. Malware on servers captured track data from Feb 16 to July 7, 2016. Total affected count unknown; substitute notification via website/press release issued.
- Massachusetts State AGas victim2016-08-31
Kimpton Hotels & Restaurant Group LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2016-08-31. 5,584 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2016-08-31
Kimpton Hotels & Restaurants Group, LLC experienced a data breach involving malware installed on servers processing payment cards at hotel front desks and restaurants. The incident occurred between February 16, 2016, and July 7, 2016, and was discovered on July 15, 2016. The malware captured track data from magnetic stripes, including card numbers, expiration dates, and verification codes, and in some cases, cardholder names. The company notified law enforcement, engaged cybersecurity firms, and is notifying affected guests.
- Washington State AGas victim2016-08-31
Kimpton Hotels & Restaurants notified Washington AG of a malware incident affecting payment card track data (PCI) at select hotels and restaurants from Feb 16 to July 7, 2016. Discovered July 15, 2016. 5,428 Washington residents notified. Malware captured card numbers, expiration dates, and verification codes.
- Oregon State AGas victim2016-08-31
Kimpton Hotels & Restaurant Group, LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2016-08-31. The breach occurred during 2/16/2016. The breach was discovered on 7/15/2016. 1 individuals were affected. Notice was sent on 8/31/2016.
- Montana State AGas reporting2016-08-31
Gray Television, Inc. notified employees that a thumb drive containing unencrypted employee information (including SSNs, names, and compensation data) was lost or stolen in a package mailed to an insurance carrier on or before August 12, 2016. The company offered one year of credit monitoring services.