CSIDB logo
Incident

Holiday Valley Resort

Incident posture

Attack window
Oct 2014
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-01-17 15:08

Linked entities

Victim
Holiday Valley Resort
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Oct 2014
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Holiday Valley Resort experienced a payment card breach involving malware on point-of-sale systems across its facilities, potentially compromising names, credit/debit card numbers, expiration dates, and CVV codes over several months. The resort removed the malware, engaged forensic experts to investigate and enhance security, and notified law enforcement and financial institutions. Due to incomplete guest contact details, direct victim notifications were not possible, but payment processors and banks were alerted to facilitate indirect outreach. Affected individuals were offered complimentary credit repair services, though the total number of victims remains undisclosed.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In June 2015, New York-based Holiday Valley Resort publicly disclosed a payment card breach potentially affecting customers who used credit or debit cards at its point-of-sale (POS) systems between October 17, 2014, and June 2, 2015. The resort's investigation revealed malware had infected multiple POS devices across its operations, including food and beverage outlets, recreation facilities, retail stores, and lodging services. This malware exposure created risk for the unauthorized capture of customers' payment card details, specifically names, card numbers, expiration dates, and three-digit CVV security codes. The resort did not disclose the exact number of impacted individuals but confirmed the compromise window spanned over seven months. Due to technical limitations in matching exposed card account numbers with complete customer contact details, Holiday Valley Resort could not directly notify potentially affected guests via email, mail, or phone.

Upon detecting the malware, Holiday Valley Resort initiated containment by removing the malicious software from its POS systems and declaring it safe for customers to resume card transactions. The organization engaged an unspecified third-party forensic firm to investigate the intrusion's origin and scope while implementing enhanced security measures to prevent recurrence. Notifications were made to law enforcement agencies, payment card processors, and relevant financial institutions, with the expectation that banks would directly alert compromised cardholders. The resort maintained publicly accessible FAQs and breach notification letters on its website to inform customers about the incident. As remediation for potential financial harm, Holiday Valley Resort offered affected guests one year of complimentary credit repair services. The forensic investigation remained ongoing at the time of the June 2015 disclosure, with no additional attacker motives or methodologies specified in available reports.

Sources

Sources available to members: 1 source.

CSIDB