Hard Rock International reported a security incident involving its third-party provider, Sabre Hospitality Solutions. An unauthorized party gained access to Sabre's SynXis Central Reservations system using valid account credentials between August 10, 2016, and March 9, 2017. The breach exposed unencrypted payment card information (cardholder name, number, expiration date, CVV) and guest reservation details (name, email, phone, address). Sabre engaged a cybersecurity firm, notified law enforcement, and informed payment card brands. The notification was filed with the California Office of the Attorney General on May 17, 2017.