On June 16, 2025, the ransomware group known as Play added Vacation Myrtle Beach to its leak site, claiming that internal files had been exfiltrated from the South Carolina-based vacation rental company.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Vacation Myrtle Beach
Get alerted the next time Vacation Myrtle Beach files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Vacation Myrtle Beach’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates the company operates vacation rental properties in the Myrtle Beach area. The Play ransomware group posted a notice on its dark-web leak site stating that it had obtained internal documents during a ransomware incident. No specific count of affected individuals has been released, and the precise volume or type of data remains unclear beyond the general description of internal files. The listing appeared on the Play leak site, which is tracked by ransomware monitoring services such as ransomware.live. As of the publication of this article, Vacation Myrtle Beach has not issued a public statement confirming the breach or detailing what customer or employee information may have been taken.
Why This Matters for You and Your Family
When a company that handles vacation bookings suffers a breach, the information it stores often includes names, addresses, phone numbers, email addresses, payment details, and sometimes dates of travel for you and your family. Even if the exact data set is not yet public, internal files from a rental business frequently contain enough personal information to fuel identity theft, phishing campaigns, or unwanted solicitations. Families who have rented properties through such services in recent years should assume their contact details could now be in the hands of criminals. The absence of a clear victim count does not mean you are unaffected; it simply means the company has not yet disclosed the scope.
The Doxxing and Identity-Chain Risks
Credential leaks and internal documents from hospitality providers frequently cascade into larger doxxing chains. An email address or phone number exposed in one breach can be linked to gaming accounts, social-media handles, or family-member profiles. Once attackers map these connections, they can target children’s gaming accounts that reuse the same password or recovery email. This creates a pathway from a simple vacation booking to full identity exposure. Available reporting describes how such chains allow criminals to escalate from data theft to harassment, account takeovers, and extortion. Protecting against these linked exposures requires more than changing a single password.