Company Details
hershey-entertainment-&-resorts
2,117
38,817
7211
hersheyentertainmentandresorts.com
2
HER_3192708
Completed

Hershey Entertainment & Resorts Company Company CyberSecurity Posture
hersheyentertainmentandresorts.comLearn more about Hershey Entertainment & Resorts, including our Core Purpose, history, and breadth of properties with our new video - https://www.youtube.com/watch?v=Rm07tDRWPBY. Human Resources Support Center at 27 West Chocolate Ave, Hershey Press Building. For assistance, call 717-534-3178. Welcome to Hershey Entertainment & Resorts Company (HE&R), an award-winning entertainment & hospitality organization with properties including: Hersheypark, The Hotel Hershey, Hershey Bears American Hockey League team, Hershey Lodge, and numerous restaurants. HE&R is a sought-after employer where our team members have fun, are welcomed for their differences and get to work in historic settings with the smell of chocolate in the air. Our team-focused and service-oriented culture is paramount to our success. We are a community-minded, family-focused organization that strives to deliver memorable experiences to guests and employees alike. With a robust Training & Development program, welcoming environment for all team members, enviable perks and 'sweet' working environments, we invite you to visit www.HersheyJobs.com to apply for a position with us! HE&R is a privately held company founded in 1927 when our founder, Milton S. Hershey, separated his chocolate manufacturing operations from his other businesses. Our nearly 1,750 full-time and more than 7,000 seasonal/part-time employees share a common goal of upholding the legacy of our founder while striving to live by our company's Core Values: Devoted to the Legacy, Selfless Spirit of Service, Team Focused, and Respectful of Others. OUR CORE PURPOSE: Hershey Entertainment & Resorts Company is proud to help fulfill the dream of our founder, Milton S. Hershey, by providing value to Milton Hershey School® in its mission of helping students lead happy, healthy, and fulfilling lives - just as Mr. Hershey wanted. Learn more at www.MHSKids.org.
Company Details
hershey-entertainment-&-resorts
2,117
38,817
7211
hersheyentertainmentandresorts.com
2
HER_3192708
Completed
Between 750 and 799

HERC Global Score (TPRM)XXXX

Description: Hershey Park, a popular resort and amusement park in Hershey suffered a data breach incident back in 2015. The incident was noticed after some of the people that visited Harshey Park reported a pattern of fraudulent activity on their payment cards. The park engaged an external computer security firm to assist and investigate the incident.


No incidents recorded for Hershey Entertainment & Resorts Company in 2025.
No incidents recorded for Hershey Entertainment & Resorts Company in 2025.
No incidents recorded for Hershey Entertainment & Resorts Company in 2025.
HERC cyber incidents detection timeline including parent company and subsidiaries

Learn more about Hershey Entertainment & Resorts, including our Core Purpose, history, and breadth of properties with our new video - https://www.youtube.com/watch?v=Rm07tDRWPBY. Human Resources Support Center at 27 West Chocolate Ave, Hershey Press Building. For assistance, call 717-534-3178. Welcome to Hershey Entertainment & Resorts Company (HE&R), an award-winning entertainment & hospitality organization with properties including: Hersheypark, The Hotel Hershey, Hershey Bears American Hockey League team, Hershey Lodge, and numerous restaurants. HE&R is a sought-after employer where our team members have fun, are welcomed for their differences and get to work in historic settings with the smell of chocolate in the air. Our team-focused and service-oriented culture is paramount to our success. We are a community-minded, family-focused organization that strives to deliver memorable experiences to guests and employees alike. With a robust Training & Development program, welcoming environment for all team members, enviable perks and 'sweet' working environments, we invite you to visit www.HersheyJobs.com to apply for a position with us! HE&R is a privately held company founded in 1927 when our founder, Milton S. Hershey, separated his chocolate manufacturing operations from his other businesses. Our nearly 1,750 full-time and more than 7,000 seasonal/part-time employees share a common goal of upholding the legacy of our founder while striving to live by our company's Core Values: Devoted to the Legacy, Selfless Spirit of Service, Team Focused, and Respectful of Others. OUR CORE PURPOSE: Hershey Entertainment & Resorts Company is proud to help fulfill the dream of our founder, Milton S. Hershey, by providing value to Milton Hershey School® in its mission of helping students lead happy, healthy, and fulfilling lives - just as Mr. Hershey wanted. Learn more at www.MHSKids.org.


DoubleTree by Hilton hotels are distinctively designed properties that provide true comfort to today’s business and leisure travelers. From the millions of delighted hotel guests who are welcomed with the brand’s legendary, warm chocolate chip cookies at check-in to the advantages of the award-winni

Minor Hotels is a global hospitality leader with a network of more than 560 hotels across six continents. We drive growth through eight diverse hotel brands and a portfolio of related hospitality businesses. Perpetually driven by an entrepreneurial spirit, we create better brands, businesses and p

Kerzner International has built a diverse collection of iconic brands and luxury properties, earning international acclaim for pioneering destination-defining hospitality, delivering unrivalled service, and curating transformative guest experiences. We are renowned for creating hospitality brands
Aramark (NYSE: ARMK) proudly serves the world’s leading educational institutions, Fortune 500 companies, world champion sports teams, prominent healthcare providers, iconic destinations and cultural attractions, and numerous municipalities in 16 countries around the world with food and facilities ma

No loud pretense. No excess formalities. Just understated elegance you’ll feel the moment you walk into one of over 80 worldwide destinations. JW Marriott is part of Marriott International’s luxury portfolio and consists of beautiful properties in gateway cities and distinctive resort locations in

Established in 1975, ITC Hotels Limited has grown to encompass over 140+ hotels across 90+ destinations, solidifying its presence in the Indian subcontinent ITC Hotels seamlessly blends India’s rich tradition of hospitality with globally benchmarked services, offering a collection of hotels and res

An IHG hotel. IHG Hotels & Resorts [LON:IHG, NYSE:IHG (ADRs)] is a global hospitality company, with a purpose to provide True Hospitality for Good. At Holiday Inn Express, we strive to make every interaction you have with us simple, smart and refreshingly engaging. With over 3,000 hotels in 75 di
We are Accor We are more than 290,000 hospitality experts placing people at the heart of what we do, creating emotion for our guests, and nurturing passion for service and achievement beyond limits. Building on the strength of our teams and of our fully integrated ecosystem of leading brands, perso
Whitbread PLC is the owner of the UK’s favourite hotel chain, Premier Inn, as well as restaurant brands, Beefeater, Brewers Fayre, Table Table, Bar + Block and Cookhouse and Pub. Whitbread employs more than 35,000 people in more than 1,200 Premier Inn hotels and restaurants across the UK and German
.png)
Grammy Award-nominated Christian music artist Forrest Frank is coming to Hershey. The singer's 29-stop “The Jesus Generation Tour” includes...
HERSHEY, Pa. (WHTM)– GRAMMY-nominated artist Forrest Frank will perform in Hershey in 2026. According to Hershey Entertainment, Forest Frank...
The season of gift-giving is here! In our minds, there is no sweeter present for a loved one (or yourself) than giving the gift of an...
Christmas in Hershey, Pa., is marked by millions of lights, family-friendly attractions and holiday coaster rides, cozy resort nights by the...
The town built on chocolate is bustling with activities to get into the holiday spirit over Thanksgiving week. From coaster rides and light...
Hershey Sweet Lights presented by PPL Electric Utilities is now open nightly through Jan. 4, 2026. For more than 20 years, the two-mile,...
It's a tell-tale sign that the most wonderful time of the year is here when Santa and all nine of his reindeer have arrived at Hersheypark...
Canadian rock group Three Days Grace will perform at the Giant Center this spring. Three Days Grace is known for hits such as “I Hate...
Hersheypark amusement park is open for an extra weekend of Hersheypark Happy between seasons on Nov. 8-9, 2025, from 12-8 p.m. It's not...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Hershey Entertainment & Resorts Company is http://www.HersheyEntertainmentandResorts.com.
According to Rankiteo, Hershey Entertainment & Resorts Company’s AI-generated cybersecurity score is 776, reflecting their Fair security posture.
According to Rankiteo, Hershey Entertainment & Resorts Company currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Hershey Entertainment & Resorts Company is not certified under SOC 2 Type 1.
According to Rankiteo, Hershey Entertainment & Resorts Company does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Hershey Entertainment & Resorts Company is not listed as GDPR compliant.
According to Rankiteo, Hershey Entertainment & Resorts Company does not currently maintain PCI DSS compliance.
According to Rankiteo, Hershey Entertainment & Resorts Company is not compliant with HIPAA regulations.
According to Rankiteo,Hershey Entertainment & Resorts Company is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Hershey Entertainment & Resorts Company operates primarily in the Hospitality industry.
Hershey Entertainment & Resorts Company employs approximately 2,117 people worldwide.
Hershey Entertainment & Resorts Company presently has no subsidiaries across any sectors.
Hershey Entertainment & Resorts Company’s official LinkedIn profile has approximately 38,817 followers.
Hershey Entertainment & Resorts Company is classified under the NAICS code 7211, which corresponds to Traveler Accommodation.
No, Hershey Entertainment & Resorts Company does not have a profile on Crunchbase.
Yes, Hershey Entertainment & Resorts Company maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/hershey-entertainment-&-resorts.
As of December 19, 2025, Rankiteo reports that Hershey Entertainment & Resorts Company has experienced 1 cybersecurity incidents.
Hershey Entertainment & Resorts Company has an estimated 13,846 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach.
Detection and Response: The company detects and responds to cybersecurity incidents through an third party assistance with external computer security firm..
Title: Hershey Park Data Breach
Description: Hershey Park, a popular resort and amusement park in Hershey, suffered a data breach incident back in 2015. The incident was noticed after some of the people that visited Hershey Park reported a pattern of fraudulent activity on their payment cards. The park engaged an external computer security firm to assist and investigate the incident.
Type: Data Breach
Common Attack Types: The most common types of attacks the company has faced is Breach.

Data Compromised: Payment card information
Payment Information Risk: True
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Payment Card Information and .

Entity Name: Hershey Park
Entity Type: Resort and Amusement Park
Industry: Entertainment
Location: Hershey, PA, USA

Third Party Assistance: External Computer Security Firm.
Third-Party Assistance: The company involves third-party assistance in incident response through external computer security firm, .

Type of Data Compromised: Payment card information

Investigation Status: Investigated by external security firm
Post-Incident Analysis Process: The company's process for conducting post-incident analysis is described as External Computer Security Firm, .
Most Significant Data Compromised: The most significant data compromised in an incident were payment card information and .
Third-Party Assistance in Most Recent Incident: The third-party assistance involved in the most recent incident was external computer security firm, .
Most Sensitive Data Compromised: The most sensitive data compromised in a breach was payment card information.
Current Status of Most Recent Investigation: The current status of the most recent investigation is Investigated by external security firm.
.png)
Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated user to bypass intended permission restrictions via a crafted HTTP request. This allows an attacker who lacks the live queries - read permission to successfully retrieve the list of live queries.
Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of its behavior. Version 5.15.1 fixes the issue.
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with snapshot restore privileges to cause Excessive Allocation (CAPEC-130) of memory and a denial of service (DoS) via crafted HTTP request.
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) of computing resources and a denial of service (DoS) of the Kibana process via a crafted HTTP request.
Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an unauthenticated user to embed a malicious script in content that will be served to web browsers causing cross-site scripting (XSS) (CAPEC-63) via a vulnerability a function handler in the Vega AST evaluator.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.