Did 4Vacation Myrtle Beach have a data breach?
Answer
Yes. 4Vacation Myrtle Beach reported a data breach to the Indiana Attorney General on May 15, 2026.
View the official filingWhat the filing says
- Reported to
- Indiana Attorney General
- Filing date
- May 15, 2026
- Breach date
- June 14, 2025
- People affected
- Not stated in the filing
Information involved
- Full Name
- Email Address
- Mailing Address
- Phone Number
- Payment Card Information
- Billing Address
- Purchase and Reservation History
- Account Password Credentials
In plain terms
4Vacation Myrtle Beach operates within the hospitality, vacation rental, and travel booking industry, specializing in managed accommodations, resort properties, and customized vacation packages along the South Carolina coast. To facilitate seamless bookings, process multi-channel payments, coordinate guest stays, and maintain property management databases, the company routinely collects and stores vast amounts of sensitive consumer data. This repository typically includes full legal names, home mailing addresses, direct telephone numbers, personal email addresses, detailed travel itineraries, and sensitive financial instruments such as credit card numbers, billing addresses, and security CVVs. Because travelers entrust these platforms with their primary payment methods and personal identifiers to secure high-value transactions, the organization functions as a significant custodian of valuable consumer information.
In 2026, 4Vacation Myrtle Beach reported a critical security incident to the Indiana Attorney General's office, alerting consumers and regulatory bodies to an unauthorized breach of its digital network infrastructure. While exact technical forensics are continuously developing, data breaches within the travel and hospitality sector frequently involve sophisticated cybercriminal methodologies such as targeted ransomware deployment, unauthorized access to cloud-hosted reservation databases, or third-party vendor compromises within booking engine software and payment processing gateways. Hospitality platforms are particularly attractive targets for threat actors due to the high volume of transient financial data passing through their systems daily, making network perimeters vulnerable to exploitation if robust, end-to-end encryption and multi-factor authentication protocols are not rigorously maintained across all digital touchpoints.
The exposure resulting from the 4Vacation Myrtle Beach incident threatens victims with severe, long-term risks of identity theft and financial fraud. The compromise of credit card numbers, banking details, and billing information leaves consumers immediately vulnerable to unauthorized fraudulent charges, account takeover, and malicious draining of personal funds. Furthermore, when personal identifiers such as full names, mailing addresses, and email addresses are combined with detailed travel schedules and booking history, malicious actors can orchestrate highly convincing, targeted phishing campaigns. These social engineering attacks can trick victims into revealing even more sensitive data, such as Social Security numbers or login credentials for other critical financial and professional accounts.
As a commercial entity handling sensitive financial and personal information, 4Vacation Myrtle Beach is bound by state consumer protection statutes, the Indiana Deceptive Consumer Sales Act, and general common-law negligence principles that mandate reasonable and appropriate data security measures. These legal obligations require companies to implement robust administrative, technical, and physical safeguards—such as regular vulnerability scanning, secure network segmentation, and encryption of stored financial records—to protect consumer assets from unauthorized access. The occurrence of this data breach strongly indicates a failure to maintain these mandatory security standards, suggesting that existing safeguards were inadequate to withstand modern cyber threats.
Receiving a formal data breach notification letter from 4Vacation Myrtle Beach serves as definitive legal confirmation that your private records were compromised due to the company's security failure. Under modern class action jurisprudence, the receipt of such a notification and the resulting imminent risk of identity theft often provides affected consumers with immediate legal standing to participate in litigation, without requiring proof of actual fraudulent financial loss. Our law firm is actively investigating potential class action claims against 4Vacation Myrtle Beach on a contingency fee basis, meaning affected individuals pay absolutely no out-of-pocket costs, and legal fees are recovered only if a successful financial recovery is achieved on your behalf.
Commonly recommended next steps
Watch your financial accounts
Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.
Secure your online accounts
Change the password on any account that reused an exposed password and turn on two-factor authentication wherever it's offered.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Look up another company
Other breaches reported in Indiana
- Teamsters Local 17Yes — reportedIndiana
- BankYes — reportedIndiana
- PeoplesBankYes — reportedIndiana · October 8, 2026
- McKenzie Creative BrandsYes — reportedIndiana · September 30, 2026
- MEBS Global ReachYes — reportedIndiana · September 30, 2026
- Midvale Indemnity and American Family Connect Insurance CompanyYes — reportedIndiana · September 30, 2026
- American Motorcyclist AssociationYes — reportedIndiana · September 30, 2026
- Nishiyamato AcademyYes — reportedIndiana · September 30, 2026
- Deer Management Co. LLC dba Bessemer Venture PartnersYes — reportedIndiana · September 30, 2026
- 9World Acceptance CorporationYes — reportedIndiana · September 30, 2026
DataBreachSearch.com reports what was filed with state regulators. It is not legal advice, is not a law firm, and is not affiliated with any government agency or with 4Vacation Myrtle Beach.