The LINE Los Angeles, a boutique hotel located in the city’s Koreatown neighborhood, has notified guests of a data security incident that may have exposed their personal information. The hotel discovered unauthorized access to its network in late September 2025 and has since worked with cybersecurity specialists to investigate the scope of the intrusion. Companies that collect and store guest information, including hotels and hospitality businesses, are responsible for safeguarding that data from unauthorized access.
The LINE Los Angeles’s Data Breach Investigation
According to a notice filed with the California Attorney General’s office, The LINE Los Angeles became aware of potential unauthorized access to its network on September 26, 2025. The hotel engaged third-party specialists to determine the nature and scope of the incident. That investigation determined that the unauthorized access to the network occurred between September 25 and October 1, 2025.
Following the investigation, The LINE Los Angeles conducted a review of the information that may have been affected in order to identify which individuals needed to be notified and what categories of their information were involved. The hotel has stated that the process of confirming current mailing addresses for affected individuals was completed on July 2, 2026, after which formal notification letters began going out. The notice filed with California’s Attorney General does not specify a root cause for the unauthorized access, and the hotel has not publicly disclosed how many individuals in total were affected nationwide.
Data breaches affecting the hospitality industry have become increasingly common in recent years, as hotels routinely collect and retain large volumes of guest information, including names, contact details, and payment information, making them attractive targets for cybercriminals. Even when the specific data elements exposed in a given incident are limited, the exposure of a guest’s name in combination with other account or reservation details can still be leveraged by bad actors for follow-up phishing attempts or identity-theft schemes, particularly when combined with information from other publicly available sources.
The nearly ten-month gap between the discovery of unauthorized network access in September 2025 and the July 2026 notification letters is longer than many state data-breach notification laws generally contemplate, though notification timelines can be extended by the complexity of a forensic investigation or by law enforcement involvement. The LINE Los Angeles’s notice states that the delay stemmed in part from the time required to identify affected individuals and locate current mailing addresses for them. Regardless of the reason for a delayed notification, the practical impact on affected individuals is the same: a longer window in which exposed information could potentially be misused before those individuals are aware their data may have been compromised.
Hospitality-industry breaches like this one are frequently traced back to compromised employee credentials, unpatched network vulnerabilities, or third-party vendors with access to a hotel’s systems, since hotels often rely on numerous connected platforms for reservations, point-of-sale transactions, and guest services. Even when a company’s own filed notice does not disclose the specific cause of an intrusion, the underlying risk to guests remains the same: any personal information stored in a hotel’s systems can potentially be accessed, copied, or sold if network defenses are breached. This is one reason state legislatures, including California, have enacted data-breach notification laws requiring companies to inform affected individuals once an incident involving personal information has been discovered and investigated.
When a notification letter states that a person’s name was involved in combination with other categories of information, without listing every category explicitly in the version filed publicly with a state Attorney General, that phrasing is fairly common in breach notices and does not necessarily mean the exposure was minor. It typically reflects that the company is providing a more complete, individualized description of the specific data elements involved to each affected person directly, rather than disclosing every possible category in the general sample notice. Affected individuals should treat the letter addressed to them as the authoritative source for what specific information about them may have been involved, and should not assume less was exposed simply because the publicly filed sample notice is less detailed.
The nearly ten-month gap between The LINE Los Angeles’s discovery of the incident in late September 2025 and the July 2026 notification also reflects a broader pattern seen across many data breach investigations: forensic reviews of what data was accessed, and efforts to compile accurate mailing information for every affected individual, can take many months, particularly when a company must coordinate with outside cybersecurity firms and mailing vendors. During that gap, affected individuals have no way of knowing their information may have been compromised, which is part of why prompt review of any notification letter, once received, and immediate enrollment in any offered monitoring service are recommended as soon as possible after notice is finally provided.
Guests who stayed at or otherwise interacted with The LINE Los Angeles around the affected period should carefully review any notification letter they receive and take the recommended precautions, including enrolling in the complimentary credit monitoring service the hotel is offering.
When Did This Breach Occur?
The unauthorized access to The LINE Los Angeles’s network occurred between September 25 and October 1, 2025, with the hotel first becoming aware of the incident on September 26, 2025. Notification letters to affected individuals were not sent until July 2026, following completion of the hotel’s internal investigation and an effort to identify current mailing addresses for those affected.
What Information Was Breached?
The notice filed with the California Attorney General states that the information that may have been involved includes an affected individual’s first and last name, in combination with other personal information. The hotel’s own filed notice does not specify what that additional information consisted of for any given individual, and The LINE Los Angeles has not otherwise publicly detailed a specific list of exposed data categories. Individuals who receive a notification letter directly from the hotel should review it carefully, as it may include details specific to their own record.
What You Can Do
If you received a notice from The LINE Los Angeles about this breach, consider taking the following steps to help protect yourself:
- Enroll in the complimentary credit monitoring service offered in the notification letter.
- Regularly review your credit reports and financial account statements for unfamiliar activity.
- Consider placing a fraud alert or credit freeze with the major credit bureaus.
- Be cautious of unsolicited calls, texts, or emails referencing your stay at The LINE Los Angeles, as scammers sometimes use breach notifications as a pretext for phishing attempts.
- Report any suspected identity theft or fraud to your local law enforcement, your state Attorney General, and the Federal Trade Commission.
File a Data Breach Lawsuit Against The LINE Los Angeles
If you received a notice from The LINE Los Angeles about this data breach, you may have legal options available to you. Companies that collect personal information have an obligation to protect it, and when that obligation is not met, affected individuals may be entitled to compensation.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.