The LINE Los Angeles, a boutique hotel in Koreatown and part of the LINE Hotel group, has notified guests of a data breach affecting personal information stored on its network. The company filed notice with the California Attorney General on July 24, 2026.
According to the notification letter, The LINE Los Angeles became aware of unauthorized network access on September 26, 2025, and its investigation determined the intrusion actually occurred between September 25 and October 1, 2025. Notification letters to affected guests are dated July 23, 2026 — nearly ten months after the breach was discovered.
A Ten-Month Gap Before Guests Were Told
The hotel’s own letter states that it spent the intervening months conducting a review to determine what information was affected and “working to obtain up-to-date address information” for guests; that process wasn’t finished until July 2, 2026. Whatever the reason, guests whose information was exposed went nearly a year without knowing they might need to watch their accounts or freeze their credit.
What Information Was Exposed?
The notification letter confirms that affected data included guests’ first and last name, in combination with other personal information, but the specific additional data type is redacted in the copy of the notice we’ve reviewed and has not been independently confirmed elsewhere. California’s Attorney General does not publish a population figure or itemized data-type list for this filing, so if you received a letter directly from The LINE, that letter is currently the most specific source on exactly what of yours was involved; we’d encourage you to send us a copy so we can help you understand it.
How Many Guests Are Affected?
Not publicly disclosed. California Attorney General filings of this kind don’t require the company to publish a total population figure, and no independent reporting has surfaced a number as of this writing.
What Is The LINE Offering?
The LINE Los Angeles is offering 12 months of complimentary online credit monitoring through TransUnion/Cyberscout. Guests must enroll themselves within 90 days of the date of their letter (July 23, 2026); the hotel states it cannot enroll guests directly due to privacy laws.
Your Information Is at Risk
Even a name paired with a single additional piece of personal information can be enough to enable targeted phishing, account takeover attempts, or identity fraud, especially when a guest can’t yet confirm exactly what was exposed. Anyone who received a notice from The LINE should treat it seriously, regardless of how the letter frames the risk.
Do You Have Legal Options?
Companies that collect guest information have a legal duty to protect it and to notify affected individuals without unreasonable delay. A ten-month gap between discovering an intrusion and telling the people affected raises real questions about whether that duty was met here.
Contact the Data Breach Attorneys at Emery | Reddy today for a Free Case Review.
Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.
FAQ
How many guests were affected by The LINE Los Angeles data breach?
Not publicly disclosed. California AG filings of this type don’t require a published population figure.
What information was exposed?
Guests’ names in combination with other personal information; the specific additional data type is not independently confirmed in the version of the notice we’ve reviewed. Send us your letter, and we can help you understand it.
Why did it take so long to be notified?
The LINE discovered the intrusion on September 26, 2025, but individual notification letters weren’t sent until July 23, 2026 — nearly ten months later. The hotel says it needed that time to determine what was affected and locate current addresses for guests.
What should I do if I received a letter?
Enroll in the free 12-month credit monitoring offer within 90 days, place a fraud alert or credit freeze with Equifax, Experian, and TransUnion, monitor your accounts closely, and consider speaking with a data breach attorney about your options.