Drury Hotels Company, LLC reported a data breach involving a third-party technology service provider used for third-party online booking reservations. Unauthorized access occurred between December 28, 2017, and June 2, 2019. The incident exposed guest names, addresses, payment card numbers, expiration dates, and verification codes. Drury notified 359 California residents via mail, email, and a press release/website notice. The service provider engaged a cybersecurity firm to investigate and implement security enhancements.
Affected (this filing): 359