DisclosureLens
HackingHospitalityHospitalityStolen CredentialsCustomer Data InvolvedGovernment IDFinancial accountHealth (basic)PIIMediumContained

Towne Vacations Deep Creek, LLC

bd_7265931baa54e926 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Oct 11, 2024

Filed

Feb 20, 2025

To disclose

19 weeks

Affected

289state residents only

Linked

3 filings

Confidence

67%
Full breach record for Towne Vacations Deep Creek, LLC

Towne Vacations Deep Creek, LLC (t/a Railey Vacations) notified the Maryland AG of a security incident discovered on October 11, 2024, involving unauthorized access to an employee's email account. The incident affected 289 Maryland residents, exposing SSNs, driver's licenses, passport numbers, financial account details, and clinical/treatment information. The company engaged third-party cybersecurity specialists, notified affected individuals, and offered 24 months of identity protection services.

Maryland clock MD AG >90d19 weeks discovery → filing

Incident timeline

discovery → filing · 19 weeks / 132 days

Oct 11, 2024

Discovered

Feb 20, 2025

Filed

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
Massachusetts State AGFeb 20 · first
Indiana State AGFeb 20 · first
Maryland State AGFeb 20 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.