LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Maine Course Hospitality Group Data Breach Notice (Vermont Attorney General)

CRITICAL severityConfirmedHow we verify

Maine Course Hospitality Group Data Breach Notice (Vermont Attorney General): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·July 31, 2026
Maine Course Hospitality Group Data Breach Notice (Vermont Attorney General)

Reported July 31, 2026. Approximately 553 people affected.

CRITICAL
Severity
553
People affected
1
Data types exposed
July 31, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Maine Course Hospitality Group has disclosed a data breach affecting 553 individuals, exposing Social Security numbers, government ID numbers, and health records. The breach notice was filed with the Vermont Attorney General on July 31, 2026; anyone who may have been affected should review the notice and take appropriate protective steps.

Severity & verification
CRITICAL severityConfirmed
Exposes government-ID/medical data.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
553 accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Maine Course Hospitality Group notified affected individuals and reported a data breach to the Vermont Attorney General on July 31, 2026. Public filings state that 553 people were affected and that the exposed information included Social Security numbers, government ID numbers, and health records.

The disclosure is limited to those core details. For people whose data may have been involved, the combination of identity documents and health information raises practical risks of fraud and misuse that warrant careful follow-up even when the full technical picture remains incomplete.

What happened

According to the notice filed with the Vermont Attorney General and reported on July 31, 2026, Maine Course Hospitality Group experienced a data breach that prompted formal notification to Vermont residents. The filing identifies 553 people as affected. The notice lists Social Security numbers, government ID numbers, and health records among the categories of information exposed.

Public detail does not describe how the incident was discovered, the precise timeline of unauthorized access, the systems involved, or the method used. No additional counts, file inventories, or dollar figures appear in the disclosed summary. The available record is therefore limited to the organization’s notification, the reported number of people affected, and the named data types.

How a breach like this happens

Incidents that result in exposure of identity and health-related records commonly begin with unauthorized access to systems that store employee, guest, or customer information. Typical pathways, described here only as general background and not as findings about this specific event, include compromised credentials, phishing that yields remote access, misconfigured remote services, or malware that reaches databases or document repositories.

Once inside an environment, an attacker or unauthorized party may copy files or database extracts containing personal identifiers and medical or insurance-related records. Organizations in hospitality and related services often retain such data for employment, payroll, benefits, guest services, or regulatory purposes. Detection can lag if logging is incomplete or if the activity blends with normal administrative use. Notification then follows legal timelines once the organization determines what categories of data were involved and which individuals appear in the affected sets. No threat group is named in the public filing for this incident, and none should be assumed.

Who is Maine Course Hospitality Group?

Maine Course Hospitality Group operates in the hospitality sector. Organizations of this type typically manage hotels, inns, restaurants, or related lodging and food-service operations. In the ordinary course of business they may hold employee records (including tax and benefits data), guest or membership information, and sometimes health-related details connected to workplace injuries, insurance, or wellness programs.

A breach affecting such an organization is consequential because hospitality groups often maintain both government identifiers required for employment and sensitive personal or health information. Even a relatively modest headcount of affected individuals can include current and former staff or others whose records were retained for legitimate business reasons. The Vermont filing indicates that at least some of those people reside in or have ties to Vermont, which triggered the state attorney general notice.

What was likely exposed

The notice explicitly names Social Security numbers, government ID numbers, and health records as among the information exposed. Those categories are confirmed by the filing. Beyond that list, the exact fields, record formats, or additional data elements are not detailed in the public summary.

Organizations in this sector commonly hold related items such as names, addresses, dates of birth, contact details, and employment or benefits paperwork; whether any of those appeared in the same incident is unconfirmed. Readers should treat only the named categories as established by the disclosure and regard everything else as unknown until further official updates appear.

Why it matters

Social Security numbers and government ID numbers are durable identifiers. Once exposed, they can be misused for tax fraud, new-account fraud, or identity theft that may surface months later. Health records add a further layer of sensitivity: they can contain diagnoses, treatment notes, or insurance details that enable targeted scams or cause lasting privacy harm if circulated.

For the 553 people listed as affected, the practical consequences include the need to monitor credit and benefits accounts, watch for unexpected medical or tax correspondence, and consider placing fraud alerts. For the organization, the incident carries notification costs, potential regulatory scrutiny, and the operational burden of supporting individuals who seek clarification or remediation. The filing does not establish negligence or assign fault; it simply records that a breach occurred and that specific data types were involved.

What to do if you're exposed

If you believe you may be among those affected, take measured steps grounded in the information that has been confirmed.

Keep records of any correspondence and of steps you take. If new official details are released by the organization or by regulators, adjust your response accordingly. Public information on this incident remains limited to the July 31, 2026 Vermont filing and the facts summarized above.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

CompanyMaine Course Hospitality Group security record
53/100
DoxxScan™ · Elevated doxx risk
D- 44Very poor record

2 reported incidents on record.

See Maine Course Hospitality Group’s full breach history →
RelatedMore incidents at Maine Course Hospitality Group

More recent breaches

Carolina Internal Medicine Data Breach Notice (Vermont Attorney General)August 21, 2026ASOS US Sales LLC Data Breach Notice (Vermont Attorney General)August 21, 2026Apollo Management Holdings, L.P. Data Breach Notice (Vermont Attorney General)August 21, 2026Monmouth University Data Breach Notice (Vermont Attorney General)August 20, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Maine Course Hospitality Group Data Breach Notice (Vermont Attorney General) →

Source: Vermont Attorney General breach notification

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram