Data BreachInvestigation Open

HUDSON RIVER PARTNERS I L.P. D/B/A THE THAYER HOTEL Data Breach

HUDSON RIVER PARTNERS I L.P. D/B/A THE THAYER HOTEL was the subject of a data breach notification filed with the IL Attorney General. The AG filing was recorded on October 17, 2025.

IL
State Filed
Oct 17, 2025
AG Filing Date
Unknown
Records Affected

Data Exposed

Full NameDate of BirthMailing AddressEmail AddressPhone NumberPayment Card Information+2 more

Tell Us About Your Notice Letter

Received a data breach notification letter? Fill out the form — an attorney will review your mailing and contact you. No cost, no obligation.

Start typing to find a matching case, or enter a company not yet listed.

Attach a copy of your data breach notification letter. Accepted: PDF, JPG, PNG — max 10 MB.

No attorney-client relationship is created by submitting this form. Attorney Advertising.

What Happened

HUDSON RIVER PARTNERS I L.P. D/B/A THE THAYER HOTEL was the subject of a data breach notification filed with the IL Attorney General. The AG filing was recorded on October 17, 2025.

Hudson River Partners I L.P., operating as The Thayer Hotel, is a premier historic hospitality and event venue situated on the grounds of the United States Military Academy at West Point, New York. Catering to high-profile guests, military officials, corporate executives, wedding parties, and tourists, the hotel collects and maintains extensive personal, financial, and logistical data. Because guests frequently book extended stays, host private events, and provide comprehensive credit card and identity verification details, the institution holds a vast repository of sensitive information necessary for reservations, billing, security vetting, and hospitality management. In 2025, Hudson River Partners I L.P. reported a significant data security incident to the Illinois Attorney General, impacting consumers whose information was entrusted to the facility. While formal disclosures continue to evolve, hospitality industry data breaches typically involve sophisticated cyberattacks such as unauthorized access to legacy reservation databases, point-of-sale (POS) system intrusions, or third-party vendor compromises. In the hospitality sector, malicious actors frequently exploit vulnerabilities in network perimeters or booking portals to deploy malware or ransomware, enabling them to quietly exfiltrate sensitive guest and employee records over extended periods before detection. The data compromised in incidents of this nature typically includes full names, home addresses, email addresses, phone numbers, date of birth, credit or debit card numbers, security codes, and reservation itineraries. For employees and staff, breaches at hospitality venues frequently expose Social Security numbers, banking details for direct deposit, and tax withholding documentation. The exposure of financial account numbers and payment card details creates an immediate and severe risk of unauthorized charges, fraudulent purchases, and financial account takeover. Furthermore, when personal identifiers are combined with travel habits and contact information, victims face heightened exposure to targeted phishing schemes, identity theft, and fraudulent loan applications. As a commercial enterprise handling sensitive consumer and employee information, Hudson River Partners I L.P. had a legal duty to implement and maintain robust administrative, physical, and technical safeguards to secure its digital environment. Under state consumer protection statutes, the Federal Trade Commission (FTC) Act, and applicable common law standards, businesses are required to reasonably protect stored data against foreseeable cyber threats. The occurrence of a successful breach often indicates a failure to maintain adequate network segmentation, patch known software vulnerabilities, encrypt sensitive consumer data, or properly vet third-party vendors with network access, representing a potential breach of these foundational legal obligations. Receiving a data breach notification letter from Hudson River Partners I L.P. serves as formal legal acknowledgment that your personal or financial information was compromised due to corporate security failures. Under modern class action jurisprudence, the receipt of such a notice establishes legal standing to pursue claims against the company for negligence, breach of implied contract, and violations of consumer protection laws, without requiring proof of actual fraudulent financial loss. Our law firm is investigating potential class action lawsuits on behalf of all affected individuals. We handle these cases on a contingency fee basis, meaning you pay nothing out of pocket, and there are no attorney fees unless we successfully recover compensation on your behalf.

What's at Risk for You

Based on the data types reported, affected individuals face:

Identity Theftcritical risk

Your SSN is the master key to your identity. Once exposed, criminals can open new lines of credit, take out loans, or file taxes in your name.

Identity Verification Bypassmedium risk

Combined with a name and other leaked data, date of birth helps criminals pass identity verification questions at banks and government agencies.

SIM Swap & Vishingmedium risk

Phone numbers exposed in breaches are used for SIM swapping attacks — hijacking your number to bypass two-factor authentication on financial accounts.

Do You Qualify for Compensation?

  • ✓You received a written data breach notification letter from HUDSON RIVER PARTNERS I L.P. D/B/A THE THAYER HOTEL
  • ✓You are or were a customer, patient, or employee of HUDSON RIVER PARTNERS I L.P. D/B/A THE THAYER HOTEL
  • ✓Your information was held by HUDSON RIVER PARTNERS I L.P. D/B/A THE THAYER HOTEL in IL

Your Rights as a Victim

What the Illinois Personal Information Protection Act (PIPA) and federal statutes entitle you to recover:

Lost Time & Remediation Costs

The hours spent responding to a data breach — canceling accounts, contacting credit bureaus, updating passwords, and investigating fraud — represent compensable economic harm in data breach litigation.

Identity Theft Protection Costs

Once your SSN is exposed, protection becomes an ongoing expense. Plaintiffs in data breach settlements have recovered costs for credit freezes, identity protection subscriptions, and time spent dealing with fraudulent accounts — sometimes covering multiple years of exposure.

Statutory Minimum Damages

Several state data breach laws provide for statutory minimum damages — fixed amounts recoverable per affected individual regardless of actual loss. These provisions exist specifically to make legal action viable for victims who have not yet experienced direct harm.

Note: an attorney general breach filing does not by itself establish a settlement fund, a payment amount, or a claim deadline. If an official settlement notice is later issued, rely on that notice for payment details and deadlines.

Frequently Asked Questions

Do I need proof that my data was misused to file a claim against HUDSON RIVER PARTNERS I L.P. D/B/A THE THAYER HOTEL?

No. Under Illinois Personal Information Protection Act (PIPA) and federal law, the unauthorized exposure of your personal data — regardless of whether it has been actively misused — can be sufficient grounds for a claim. The breach itself is the injury.

How much does filing a claim cost?

Nothing. The Law Office of David S. Harris handles data breach cases on contingency — you pay zero upfront and owe nothing unless compensation is recovered.

My Social Security Number was exposed. What should I do right now?

Immediately place a free credit freeze at all three bureaus (Equifax, Experian, TransUnion). A freeze blocks new accounts from being opened in your name. Then file a complaint with the FTC at IdentityTheft.gov and contact our office — SSN exposure is one of the most serious breach types.

Is it too late to file a claim?

Statutes of limitations for data breach claims vary by state but typically run 2–4 years. Depending on when you learned of the breach, you may still have time. Contact our office for a free eligibility review — there is no cost to find out.

What if HUDSON RIVER PARTNERS I L.P. D/B/A THE THAYER HOTEL offered me free credit monitoring after the breach?

Accepting free credit monitoring from HUDSON RIVER PARTNERS I L.P. D/B/A THE THAYER HOTEL does not waive your right to pursue legal action unless you signed a specific release waiving claims. In most cases, victims who accepted monitoring can still file.

Do I need to have received a notice letter to be eligible?

Not necessarily. Many data breach victims are never notified directly. If your personal information was held by HUDSON RIVER PARTNERS I L.P. D/B/A THE THAYER HOTEL during the relevant period, you may still qualify even without receiving a letter. A free eligibility review can confirm your status.

How long does a data breach class action lawsuit take?

Most data breach class actions resolve within 18 to 36 months, though timelines vary by court and complexity. Your participation requires minimal effort — typically completing a claim form. Our office handles all litigation; you are notified when a settlement is reached.

Received a notification letter from HUDSON RIVER PARTNERS I L.P. D/B/A THE THAYER HOTEL?

What it means and what to do next.

Letter Guide →

HUDSON RIVER PARTNERS I L.P. D/B/A THE THAYER HOTEL breach?

Free case review · No fee unless you win

Call Now