Inntopia
ent_c6f616bc112597229bf8cca9
Disclosures
7
State AG · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
98,728
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Inntopia
- Normalized
- inntopia— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- inntopia.com
Disclosure history (7)newest first
- Maine State AGas victim2022-10-11
Sterling Valley Systems, operating as Inntopia, reported an external system breach that occurred between October 9, 2021, and February 18, 2022. The breach was discovered on March 2, 2022. The compromised data includes names and financial account numbers or credit/debit card numbers along with their security codes, access codes, passwords, or PINs. A total of 330 Maine residents were affected. In response, the company offered 12 months of identity theft protection services through Experian.
- California State AGas victim2022-05-23
Sterling Valley Systems d/b/a Inntopia reported that an unknown actor gained access to payment card information on its e-commerce reservation platform between October 9, 2021, and February 18, 2022. The company discovered suspicious activity on February 18, 2022. Affected data includes credit/debit card numbers and potentially other identity information, but not Social Security Numbers. The company engaged third-party cybersecurity specialists, notified law enforcement and payment card brands, and is offering credit monitoring services to impacted individuals.
- Maine State AGas victim2022-05-23
Sterling Valley Systems d/b/a Inntopia reported an external system breach (hacking) occurring between October 9, 2021, and February 18, 2022, discovered on March 2, 2022. The incident affected 68,635 individuals, including 329 Maine residents. Acquired data included names and financial account or credit/debit card numbers (with security codes/PINs). Inntopia sent written notifications and provided 12 months of credit monitoring and identity theft protection through Experian.
- Maine State AGas victim2022-04-12
Sterling Valley Systems, d/b/a Inntopia, a hospitality technology provider, experienced an external system breach. The breach, which occurred between October 2021 and February 2022, resulted in the unauthorized acquisition of customer names and financial account information. The company discovered the breach in March 2022 and notified affected individuals in April 2022, offering 12 months of credit monitoring services.
- Washington State AGas victim2022-04-05
Sterling Valley Systems d/b/a Inntopia reported unauthorized access to its e-commerce platform between October 9, 2021, and February 18, 2022. An unknown actor accessed payment card information, names, dates of birth, and security codes. The incident was discovered on February 18, 2022. Approximately 13,396 Washington residents were affected. The company engaged forensic specialists, notified law enforcement, and provided 12 months of credit monitoring.
- Maine State AGas victim2022-04-05
Sterling Valley Systems d/b/a Inntopia reported an external system breach (hacking) occurring between October 9, 2021, and February 18, 2022. The incident compromised the personal information and financial account numbers of 18,884 individuals, including 74 Maine residents. Inntopia notified affected consumers in writing on April 5, 2022, and provided 12 months of credit monitoring and identity theft protection services through Experian.
- California State AGas victim2022-04-05
Sterling Valley Systems d/b/a Inntopia, an e-commerce reservation platform, discovered unauthorized access to payment card information on February 18, 2022. The incident occurred between October 9, 2021, and February 18, 2022. An unknown external actor accessed credit/debit card numbers. The company engaged third-party cybersecurity specialists, notified law enforcement and payment card brands, and offered credit monitoring to affected individuals. Social Security Numbers were not involved.