Vacation Myrtle Beach Suffers Ransomware Attack, Exposing Sensitive Data of Over 10,000 Individuals
Vacation Myrtle Beach, a major oceanfront resort group in South Carolina, disclosed a data breach affecting 10,750 individuals across the U.S., including four Maine and six Vermont residents. The company sent notification letters on May 15, 2026, detailing the incident.
The breach was first detected on June 16, 2025, when the company identified suspicious activity in its network. After securing its systems, Vacation Myrtle Beach launched an investigation with independent forensic experts. Three days later, the PLAY ransomware group claimed responsibility, posting on the dark web that it had exfiltrated sensitive data including client documents, payroll records, tax information, and financial data and threatened to publish it on June 23, 2025.
The investigation confirmed unauthorized access to personally identifiable information (PII), such as names, Social Security numbers, driver’s license details, financial account data, and passport numbers. Additionally, protected health information (PHI) may have been exposed.
In response, Vacation Myrtle Beach offered affected individuals complimentary credit monitoring and identity protection services through Cyberscout (a TransUnion company), with a 90-day enrollment window from the notification date. A dedicated helpline (1-877-424-7790) was also established for inquiries.
Source: https://www.claimdepot.com/data-breach/vacation-myrtle-beach-2026
Vacation Myrtle Beach cybersecurity rating report: https://www.rankiteo.com/company/vacation-myrtle-beach
"id": "VAC1779121635",
"linkid": "vacation-myrtle-beach",
"type": "Ransomware",
"date": "6/2025",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '10750',
'industry': 'Hospitality',
'location': 'South Carolina, USA',
'name': 'Vacation Myrtle Beach',
'type': 'Resort Group'}],
'customer_advisories': 'Notification letters sent, complimentary credit '
'monitoring and identity protection services offered, '
'dedicated helpline established',
'data_breach': {'data_exfiltration': True,
'file_types_exposed': ['Client documents',
'Payroll records',
'Tax information',
'Financial data'],
'number_of_records_exposed': '10750',
'personally_identifiable_information': ['Names',
'Social Security '
'numbers',
'Driver’s license '
'details',
'Financial account '
'data',
'Passport numbers'],
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Personally identifiable '
'information (PII)',
'Protected health information '
'(PHI)']},
'date_detected': '2025-06-16',
'date_publicly_disclosed': '2026-05-15',
'description': 'Vacation Myrtle Beach, a major oceanfront resort group in '
'South Carolina, disclosed a data breach affecting 10,750 '
'individuals across the U.S. The breach involved unauthorized '
'access to personally identifiable information (PII) and '
'protected health information (PHI), with the PLAY ransomware '
'group claiming responsibility and threatening to publish '
'exfiltrated data.',
'impact': {'data_compromised': 'Personally identifiable information (PII) and '
'protected health information (PHI)',
'identity_theft_risk': 'High',
'payment_information_risk': 'High'},
'investigation_status': 'Completed',
'motivation': 'Data exfiltration and extortion',
'ransomware': {'data_exfiltration': True, 'ransomware_strain': 'PLAY'},
'references': [{'date_accessed': '2026-05-15',
'source': 'Vacation Myrtle Beach Notification'}],
'response': {'communication_strategy': 'Notification letters sent to affected '
'individuals, dedicated helpline '
'established',
'containment_measures': 'Secured systems after detecting '
'suspicious activity',
'remediation_measures': 'Offered complimentary credit monitoring '
'and identity protection services',
'third_party_assistance': 'Independent forensic experts, '
'Cyberscout (TransUnion)'},
'threat_actor': 'PLAY ransomware group',
'title': 'Vacation Myrtle Beach Ransomware Attack and Data Breach',
'type': 'Ransomware'}