Pacific Hospitality Group notified California AG that Sabre Hospitality Solutions, a third-party provider, experienced unauthorized access to its Central Reservations System (CRS) between November 2016 and March 2017. The breach exposed unencrypted payment card data (card numbers, expiration dates, potentially CVVs) and guest PII (names, emails, addresses) for a subset of reservations. Sabre engaged forensic investigators and law enforcement; access was contained. No evidence of data removal was found, though exfiltration remains possible.