Vacation Myrtle Beach, a hospitality entity, experienced an external system breach. The breach occurred on June 16, 2025, and was discovered on March 4, 2026. The company reported this incident to regulators and notified consumers by May 15, 2026.
The breach affected an estimated 10,750 individuals, including 4 Maine residents. The types of data acquired included names and other personal identifiers in combination with other, unspecified data. Vacation Myrtle Beach offered 12 months of identity theft protection services through TransUnion, including credit and dark web monitoring, a $1 million policy, and managed services. The exact nature of the additional compromised data types has not been publicly confirmed.
Details about the full scope of the breach and any further regulatory actions may emerge. Notices to affected individuals may also be delayed.