Resort Data Processing (RDP) disclosed a security event where an unauthorized actor used compromised vendor credentials to scrape customer reservation data, including names, payment card numbers, CVVs, and expiration dates. The incident occurred between December 25, 2024, and January 22, 2025. RDP engaged forensic investigators, offered one year of credit monitoring via Kroll, and implemented additional system safeguards.