Salamander Resort & Spa, a luxury resort in Middleburg, Virginia, detected unauthorized access to its systems on February 5, 2026. The Lynx ransomware group publicly claimed responsibility for the attack on their dark web leak site in February 2026. The company acted to contain the incident and has since provided updates.
The breach exposed data for approximately 45,267 individuals, primarily guests and employees. The types of data involved include names, addresses, email addresses, phone numbers, partial payment card data (last 4 digits), reservation details, employee PII, and internal documents. Limited SSNs for about 1,200 employee records were also affected. No full credit card numbers or medical data were confirmed as exposed. The company mailed notice letters to affected individuals between March 15 and March 20, 2026, and filed with the Virginia AG on March 17, 2026, along with additional notices to CA, NY, and MA AGs.
While details can emerge later and consumer notifications may be delayed, the resort has provided credit monitoring services. The incident highlights ongoing threats to the hospitality industry.