DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Grand Sierra Resort guest payment cards breached in 2014 and again in 2015

Posted on April 25, 2016 by Dissent

The Grand Sierra Resort in Reno, Nevada, has become the latest hospitality entity to disclose a data breach involving customers’ credit card information.  In this case, there appear to be two time frames during which cards used at their food and retail locations may have been compromised: for a one-month period in 2014 and again during a 5-month period in 2015.

The resort was first notified of a problem by law enforcement in September, 2015, but was not able to confirm the breach until January, 2016. Why it took so long and why it took another three months to disclose this publicly has not been explained. Nor has the number of impacted guests been disclosed or the method of the compromise.

Those affected were not offered any mitigation services such as credit monitoring, and the resort does not indicate whether card issuers were notified.

All in all, not a great situation: failure to detect compromise not once, but twice, and slow to disclose? I wonder if the FTC will investigate this one.

The following material is from the resort’s notice dated April 25, and posted on their web site:

We are writing to notify guests of an unfortunate situation regarding a data security incident that may have affected the security of certain guest payment card information. Below is information on the incident and resources available to protect potentially impacted guests against identity theft or fraud, should they feel the need to do so.

WHAT HAPPENED? On or around September 29, 2015, the Grand Sierra Resort was contacted by law enforcement regarding an investigation into a potential compromise of payment card information used at food and retail locations at the Grand Sierra Resort. We immediately began to cooperate with law enforcement and to investigate this matter. Third party forensics investigators were retained to assist the Grand Sierra Resort. On or around January 11, 2016, these investigators confirmed that certain guest payment card information for cards used at food and retail locations at the Grand Sierra Resort may have been compromised.

WHAT INFORMATION WAS INVOLVED? The investigation has determined that payment card information used at the Grand Sierra’s onsite food and retail locations between February 19, 2014 and March 13, 2014 or March 20, 2015 and August 6, 2015 could be at risk. This includes information like the cardholder’s name, credit card number, credit card expiration date, Track 1 data and Track 2 data. Please note that this incident did not affect payment cards used to book or pay for lodging.

WHAT WE ARE DOING? Since discovering the compromise, we have worked closely with law enforcement and our forensics investigators to determine what happened, what information may be at risk and to whom this information may relate. Additionally, as part of our ongoing commitment to the security of the personal information in our care, we have worked diligently to enhance existing security measures to prevent further unauthorized access to guest payment card information.

WHAT YOU CAN DO. We encourage potentially impacted guests to review the information below on how to better protect against identity theft or fraud.

FOR MORE INFORMATION. We apologize for any inconvenience and concern this incident causes you. The security of our guests’ personal information is one of our highest priorities. Should you have any questions about the content of this notice or ways you can protect yourself from the possibility of identity theft, please call our dedicated hotline at (877) 216-3789 between 9 a.m. and 7 p.m. EST, Monday to Friday. Please use reference number 6216041816 when calling.

The full notice can be found here.

Category: Business SectorID TheftU.S.

Post navigation

← 2,400 members’ info stolen, Kaiser Permanente says
Hundreds of Spotify credentials appear online – users report accounts hacked, emails changed →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Department of Justice says Berkeley Research Group data breach may have exposed information on diocesan sex abuse survivors
  • Masimo Manufacturing Facilities Hit by Cyberattack
  • Education giant Pearson hit by cyberattack exposing customer data
  • Star Health hacker claims sending bullets, threats to top executives: Reports
  • Nova Scotia Power hit by cyberattack, critical infrastructure targeted, no outages reported
  • Georgia hospital defeats data-tracking lawsuit
  • 60K BTC Wallets Tied to LockBit Ransomware Gang Leaked
  • UK: Legal Aid Agency hit by cyber security incident
  • Public notice for individuals affected by an information security breach in the Social Services, Health Care and Rescue Services Division of Helsinki
  • PowerSchool paid a hacker’s extortion demand, but now school district clients are being extorted anyway (3)

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • ARC sells airline ticket records to ICE and others
  • Clothing Retailer, Todd Snyder, Inc., Settles CPPA Allegations Regarding California Consumer Privacy Act Violations
  • US Customs and Border Protection Plans to Photograph Everyone Exiting the US by Car
  • Google agrees to pay Texas $1.4 billion data privacy settlement
  • The App Store Freedom Act Compromises User Privacy To Punish Big Tech
  • Florida bill requiring encryption backdoors for social media accounts has failed
  • Apple Siri Eavesdropping Payout Deadline Confirmed—How To Make A Claim

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.