DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Sabre Update on Cybersecurity Incident

Posted on July 5, 2017 by Dissent

SOUTHLAKE, Texas, July 5, 2017 /PRNewswire/ — Sabre Corporation (NASDAQ: SABR) issued the following statement regarding a cybersecurity incident first disclosed on May 2, 2017:

Since June 6, Sabre has notified and been working with certain customers and partners that use or interact with Sabre Hospitality Solutions’ (SHS) SynXis Central Reservations system (SHS reservation system) about our previously disclosed incident of unauthorized access. Some travel management companies (TMCs) and travel agencies that booked travelers that may have been affected have also been notified about the incident, although those TMCs and other parties do not use or interact with the Sabre SynXis system.  Our investigation is complete and we have determined that an unauthorized party accessed certain payment card information for a limited subset of hotel reservations processed through the SHS reservation system.

Not all reservations that were viewed included the payment card security code, as a large percentage of bookings were made without a security code being provided.  Others were processed using virtual card numbers in lieu of consumer credit cards.  Personal information such as social security, passport or driver’s license number was not accessed.  Sabre has notified law enforcement and the credit card brands as part of our investigation.

There is no indication that any other Sabre systems beyond the SHS reservation system, such as Sabre’s Travel Network and Airline Solutions platforms, were affected by the unauthorized party.  We have taken successful measures to ensure this unauthorized access to the SHS reservation system was stopped and is no longer possible.  Our investigation did not uncover forensic evidence that the unauthorized party removed any information from the system, but it is a possibility.

This incident was limited to a subset of bookings made through the SHS reservation system and accessed over a seven month period from August 2016 to March 2017.  Not all of our SHS customers had reservations that were accessed, and even for those that did have reservations that were viewed, it varied with regard to the percentage of reservations that were accessed. We have engaged Epiq Systems to provide complimentary consumer notice support for those customers that determine they have a notification obligation.  The data submitted to the SHS reservation system varied, as well as the geographic locations of both our customers and their respective guests, so we have worked to provide those Sabre customers that had reservations that were viewed with all available information to evaluate their affected reservations and customer lists.  A general consumer information site is available at http://sabreconsumernotice.com/ to support any direct consumer notice our customers might choose to make.

The Sabre team sincerely regrets this incident, and we appreciate the support and collaboration our partners have shown during this investigation.  Our industry, like many, faces ever increasing cybersecurity threats that require strong partnerships across the travel ecosystem.  Sabre will continue to take strong measures to protect the interests of our customers and the traveling public.

About Sabre
Sabre Corporation is the leading technology provider to the global travel industry. Sabre’s software, data, mobile and distribution solutions are used by hundreds of airlines and thousands of hotel properties to manage critical operations, including passenger and guest reservations, revenue management, flight, network and crew management. Sabre also operates a leading global travel marketplace, which processes more than US$120 billion of global travel spend annually by connecting travel buyers and suppliers. Headquartered in Southlake, Texas, USA, Sabre serves customers in more than 160 countries around the world.

SABR-F

Category: Breach Incidents

Post navigation

← While investigating one ransomware attack, Walnut Place hit with second attack
ZW: Computers with Criminal Records Stolen from Gutu Magistrate’s Court →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Resource: State Data Breach Notification Laws – June 2025
  • WestJet investigates cyberattack disrupting internal systems
  • Plastic surgeons often store nude photos of patients with their identity information. When would we call that “negligent?”
  • India: Servers of two city hospitals hacked; police register FIR
  • Ph: Coop Hospital confirms probe into reported cyberattack
  • Slapped wrists for Financial Conduct Authority staff who emailed work data home
  • School Districts Unaware BoardDocs Software Published Their Private Files
  • A guilty plea in the PowerSchool case still leaves unanswered questions
  • Brussels Parliament hit by cyber-attack
  • Sweden under cyberattack: Prime minister sounds the alarm

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Vermont signs Kids Code into law, faces legal challenges
  • Data Categories and Surveillance Pricing: Ferguson’s Nuanced Approach to Privacy Innovation
  • Anne Wojcicki Wins Bidding for 23andMe
  • Would you — or wouldn’t you?
  • New York passes a bill to prevent AI-fueled disasters
  • Synthetic Data and the Illusion of Privacy: Legal Risks of Using De-Identified AI Training Sets
  • States sue to block the sale of genetic data collected by DNA testing company 23andMe

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.