HackingStolen CredentialsCustomer Data InvolvedIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPIIMediumContained
Towne Vacations Deep Creek, LLC
bd_7265931baa54e926 · schema v1 · pii pii-v1
Full breach record for Towne Vacations Deep Creek, LLC →Towne Vacations Deep Creek, LLC (t/a Railey Vacations) notified the Maryland AG of a security incident discovered on October 11, 2024, involving unauthorized access to an employee's email account. The incident affected 289 Maryland residents, exposing SSNs, driver's licenses, passport numbers, financial account details, and clinical/treatment information. The company engaged third-party cybersecurity specialists, notified affected individuals, and offered 24 months of identity protection services.
Maryland clock✗ MD AG >90d19 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_ee898730124090c2Indiana State AGfiled 2025-02-20Verified
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376390.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 20, 2025
- Raw hash
- 174d5b7218a7d02f0195324dd0fef1ffa2c12cf04a2b368cb2ca0961410f6626
Reporting entity
- Name
- Towne Vacations Deep Creek, LLCnorm: towne vacations deep creek
Victim entity
- Name
- Towne Vacations Deep Creek, LLCnorm: towne vacations deep creek
Incident
- Discovered
- Oct 11, 2024
- Materiality determined
- —
- Notification sent
- Feb 20, 2025
- Affected individuals
- 289
- Data types
- IDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPII
- Attack vector
- Insider
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified Maryland Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 19 weeks(132 days from discovery to filing)
- Compliance flags
- MD AG >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.