The California Office of the Attorney General disclosed a data breach at South Coast Winery Resort & Spa (and its affiliated Carter Estate Winery Resort) on August 16, 2017. The incident involved unauthorized access to customer payment card systems, persisting from August 10, 2016, to March 9, 2017. During this period, attackers potentially compromised customer names, payment card details (including card numbers, expiration dates, and security codes), and reservation information. The breach exposed sensitive financial data, raising risks of fraudulent transactions, identity theft, and reputational harm to the affected individuals. While the exact number of impacted customers was not specified, the prolonged duration of the breach (over seven months) amplified the exposure window. The company likely faced regulatory scrutiny, customer distrust, and potential financial liabilities due to the failure to detect and mitigate the intrusion promptly. Payment card breaches of this nature often trigger compliance investigations (e.g., PCI DSS violations) and may result in fines or legal actions from affected parties.
Source: https://oag.ca.gov/ecrime/databreach/reports/sb24-101137
TPRM report: https://www.rankiteo.com/company/south-coast-winery-&-spa
"id": "sou718082025",
"linkid": "south-coast-winery-&-spa",
"type": "Breach",
"date": "8/2016",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Hospitality',
'location': 'California, USA',
'name': 'South Coast Winery Resort & Spa',
'type': 'Resort & Winery'},
{'industry': 'Hospitality',
'location': 'California, USA',
'name': 'Carter Estate Winery Resort',
'type': 'Resort & Winery'}],
'data_breach': {'data_exfiltration': 'Likely',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['customer names',
'payment card details',
'reservation information']},
'date_detected': '2017-03-09',
'date_publicly_disclosed': '2017-08-16',
'description': 'The California Office of the Attorney General reported a data '
'breach at South Coast Winery Resort & Spa and Carter Estate '
'Winery Resort involving unauthorized access to customer '
'payment card information. The breach occurred on August 10, '
'2016, and continued until March 9, 2017, potentially '
'affecting customer names, payment card details, and '
'reservation information.',
'impact': {'data_compromised': ['customer names',
'payment card details',
'reservation information'],
'identity_theft_risk': 'Potential',
'payment_information_risk': 'High'},
'references': [{'date_accessed': '2017-08-16',
'source': 'California Office of the Attorney General'}],
'regulatory_compliance': {'regulatory_notifications': 'California Office of '
'the Attorney General'},
'title': 'Data Breach at South Coast Winery Resort & Spa and Carter Estate '
'Winery Resort',
'type': 'Data Breach'}