HackingCustomer Data InvolvedPIIIDENTITY_BASICMediumContained
Vacation Myrtle Beach
bd_5579950393497e68 · schema v1 · pii pii-v1
Full breach record for Vacation Myrtle Beach →Vacation Myrtle Beach reported an external system breach (hacking) occurring on June 16, 2025, discovered on March 4, 2026. The incident affected 10,750 individuals total, including 4 Maine residents. The entity notified consumers via written notice on May 15, 2026, and provided 12 months of credit and dark web monitoring through TransUnion.
Leak gap clock✗ Leak >180d10 weeks discovery → filing
⚠ AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
This filing is one of 4 about the same incident.View merged incident
A leak claim by play about this victim predates this filing by 334 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_731eccc5d9a732b3Leak Siteplayfiled 2025-06-15(334d gap)Candidate
Regulatory filings (2) · sorted by filing gap
- bd_6cbdbd33c96d1ba0Indiana State AGfiled 2026-05-15Verified by operator
- bd_d6ec312fb44979dbVermont State AGfiled 2026-05-15Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/22bff34a-24aa-4aa0-95a4-b56bbe5fcc72.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 15, 2026
- Raw hash
- 3e070b37d62742e1c701324856611ed5acd9a9c4d5b6c38897a7101e6717a994
Reporting entity
- Name
- Constangy, Brooks, Smith & Prophete, LLPnorm: constangy brooks smith prophete
Victim entity
- Name
- Vacation Myrtle Beachnorm: vacation myrtle beach
- Domain
- vacationmyrtlebeach.com
Incident
- Discovered
- Mar 4, 2026
- Materiality determined
- —
- Notification sent
- May 15, 2026
- Affected individuals
- 10,750
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 10 weeks(72 days from discovery to filing)
- Compliance flags
- Leak >180dME AG >30d · 72dME resident >60d · 72d
- Discovery-date grounding
- AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Mar 4, 2026→ Filed with AG: May 15, 202672d 30 days (soft) ME AG >30d Maine Discovered: Mar 4, 2026→ Notified: May 15, 202672d 60 days (analyst band; statutory cap is 30 days) ME resident >60d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.