Attackers gained unauthorized access using the internal network credentials of two distinct franchise employees at a managed property. The adversary systematically exfiltrated guest information, including loyalty metrics, phone contacts, and physical addresses.