Clustered 6 filings across 3 jurisdictions · filing window Apr 5, 2022 → May 23, 2022. View entity profile → Other incidents for this victim →
incident inc_8783df3eeae24e86 · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
CA ME WA
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
all State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
Oct 9, 2021 → Feb 18, 2022
When the intrusion reportedly occurred, per the linked filings
Feb 18, 2022
Reported by WASHINGTON AG, CALIFORNIA AG filings
Mar 2, 2022
Reported by MAINE AG filings
Sterling Valley Systems d/b/a Inntopia disclosed a breach affecting payment card information for approximately 58 Rhode Island residents (and potentially others in DC, MD, NM, NY, NC). The incident occurred between October 9, 2021, and February 18, 2022, when an unknown actor accessed payment card data on Inntopia's e-commerce reservation platform. Inntopia engaged third-party cybersecurity specialists, notified law enforcement and payment card brands, and offered credit monitoring services.
Affected (this filing): 58
Sterling Valley Systems d/b/a Inntopia reported an external system breach (hacking) occurring between October 9, 2021, and February 18, 2022, discovered on March 2, 2022. The incident affected 68,635 individuals, including 329 Maine residents. Acquired data included names and financial account or credit/debit card numbers (with security codes/PINs). Inntopia sent written notifications and provided 12 months of credit monitoring and identity theft protection through Experian.
Affected (this filing): 68,635
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Sterling Valley Systems d/b/a Inntopia, a business sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2022-02-18 and filed notice on 2022-04-05. 13,396 Washington residents were affected. 46 days elapsed between awareness and notification. 132 days to identify the breach. 0 days to contain the breach.
Affected (this filing): 13,396
Sterling Valley Systems d/b/a Inntopia reported an external system breach (hacking) occurring between October 9, 2021, and February 18, 2022. The incident compromised the personal information and financial account numbers of 18,884 individuals, including 74 Maine residents. Inntopia notified affected consumers in writing on April 5, 2022, and provided 12 months of credit monitoring and identity theft protection services through Experian.
Affected (this filing): 18,884
Sterling Valley Systems d/b/a Inntopia, an e-commerce reservation platform, disclosed a breach occurring between October 9, 2021, and February 18, 2022. An unknown actor gained unauthorized access to payment card information (credit/debit numbers). The incident affected at least 64 Rhode Island residents, with notifications sent to individuals in multiple states. Inntopia engaged third-party cybersecurity specialists, notified law enforcement and payment card brands, and offered credit monitoring via Experian. The investigation was ongoing at the time of the notice.
Sterling Valley Systems, d/b/a Inntopia, a hospitality technology provider, experienced an external system breach. The breach, which occurred between October 2021 and February 2022, resulted in the unauthorized acquisition of customer names and financial account information. The company discovered the breach in March 2022 and notified affected individuals in April 2022, offering 12 months of credit monitoring services.
Affected (this filing): 65