Were you recently affected by a data breach?

Waterford Hotel Group Data Breach

Waterford Hotel Group and its corporate parent, LMD Holding Company, LLC, notified Vermont residents that a data security incident may have compromised their personal information, affecting 242 Vermont residents.

Waterford Hotel Group
Date of Breach: Not publicly disclosed
CAU logo

Who was affected:

Clients of Waterford Hotel Group

Impacted Data:

Specific data types not publicly disclosed by the company

Waterford Hotel Group, a hospitality management company headquartered in Waterford, Connecticut, has notified Vermont residents of a data security incident. LMD Holding Company, LLC, the corporate parent of Waterford Hotel Group, was named alongside the hotel operator in the notification filed with the Vermont Attorney General’s Office.

Companies that manage guest reservations, payment details, and other personal information for travelers take on a significant responsibility to protect that information from unauthorized access, and a lapse in that responsibility can expose guests to real and lasting harm.

Waterford Hotel Group’s Data Breach Investigation

Waterford Hotel Group operates and manages a portfolio of hotel properties, and like most hospitality companies it collects and stores substantial amounts of guest information as part of normal business operations, including reservation records, contact details, and payment information. When a data security incident occurs at a company handling this volume and sensitivity of personal data, an investigation typically follows a well-established path: the company first works to contain the incident and secure its systems, then retains forensic specialists to determine what happened, when it happened, and precisely which systems and records were affected.

According to the notification filed with the Vermont Attorney General’s Office, Waterford Hotel Group, together with its corporate parent, LMD Holding Company, LLC, reported that 242 Vermont residents may have had personal information compromised in connection with this incident. Vermont’s Attorney General’s Office no longer publishes the underlying notification letters or supporting documentation for security breach notices, citing digital accessibility requirements for government websites, so the full narrative of how the incident occurred, the specific vulnerability exploited, and the exact timeline of detection and containment have not been made publicly available beyond the entity’s name and the number of Vermont residents affected.

The hospitality sector has increasingly become a target for cybercriminals precisely because hotel companies sit at the intersection of high transaction volume, third-party vendor relationships, and large stores of personally identifiable and financial information. Reservation systems, property management software, point-of-sale terminals, and loyalty programs are all potential points of entry, and a single compromised vendor or employee credential can sometimes expose records spanning multiple properties under common ownership or management. Guests booking rooms, providing government-issued identification at check-in, and paying with credit or debit cards generate exactly the kind of data that is valuable on illicit markets, including full names, contact information, payment card numbers, and sometimes driver’s license or passport numbers.

When a notice like this is filed with a state attorney general’s office, it generally means the company has made an internal determination that the incident meets that state’s legal threshold for consumer notification, a assessment usually made only after forensic investigators have had the opportunity to examine the affected systems and logs. Attorneys general offices such as Vermont’s serve as a public clearinghouse for these filings, and the entries function primarily as a record that a notification obligation was triggered and satisfied, not as a substitute for the underlying investigative findings that a company shares directly with affected individuals.

For consumers, the fact that a specific breakdown of what was accessed has not been published does not mean the risk is any less real. Following an incident like this, affected individuals are typically encouraged to remain alert for phishing attempts referencing their hotel stay or reservation, to monitor financial accounts and credit reports for unauthorized activity, and to take advantage of any credit monitoring or identity protection services the company may offer as part of its response. Data breach investigations of this kind can also lead to broader accountability questions, including whether the company maintained reasonable security practices given the volume and sensitivity of the guest data it collected.

Vermont, like most states, requires businesses that experience a security breach affecting residents’ personal information to notify both the affected individuals and the Attorney General’s Office, generally as soon as practicable after the breach is discovered, and this requirement applies regardless of whether the breached company is headquartered in Vermont or simply does business with Vermont residents, as appears to be the case here given Waterford Hotel Group’s Connecticut headquarters. This kind of cross-border notification obligation is common in the hospitality industry, where a single hotel management company can serve guests from dozens of states through a handful of properties, meaning one security incident can trigger notification duties in many jurisdictions simultaneously, each with its own timeline and disclosure requirements. That patchwork of state-by-state rules is part of why the level of public detail available about a single breach can vary so widely from state to state, with some attorneys general publishing full notification letters and others, like Vermont, limiting the public record to summary information such as the entity’s name and the number of residents affected.

When Did This Breach Occur?

The precise dates on which this incident began, was discovered, and was contained have not been publicly disclosed. Vermont’s Attorney General’s Office confirmed that Waterford Hotel Group and LMD Holding Company, LLC filed a security breach notification affecting 242 Vermont residents, with the filing recorded on September 25, 2026. State breach notification laws, including Vermont’s, generally require covered entities to notify residents and the attorney general’s office within a defined window after discovering that personal information has been compromised, though the exact discovery date for this specific incident has not been made public.

Companies are frequently still finalizing the scope of an incident even after the initial notification obligation has been triggered, meaning additional detail about the timeline may become available as the investigation continues or as supplemental notices are filed in other states.

What Information Was Breached?

Vermont’s Attorney General’s Office does not publish the type of information involved for each individual security breach notice beyond an initial notification, and no additional public source has confirmed the specific categories of Waterford Hotel Group guest data affected in this incident. Hospitality companies of this type typically store information such as guest names, contact details, reservation and stay history, and payment card information, but affected individuals should not assume any particular category was or was not involved until the company’s own direct notice specifies what happened in their case.

Anyone who has stayed at a Waterford Hotel Group property and receives a direct notification letter should read it carefully, since that letter is the authoritative source for what specific information was involved for that individual.

What You Can Do

If you believe you may have been affected by this incident, consider the following steps:

  • Read any notification letter from Waterford Hotel Group carefully and keep it for your records.
  • Monitor your bank and credit card statements for any unauthorized or unfamiliar charges.
  • Consider placing a fraud alert or credit freeze with the three major credit bureaus.
  • Enroll in any free credit monitoring or identity protection services the company offers.
  • Be cautious of phishing emails, texts, or calls referencing a hotel stay or reservation, and never provide personal information in response to an unsolicited message.
  • Regularly check your credit reports for accounts or inquiries you do not recognize.

File a Data Breach Lawsuit Against Waterford Hotel Group

Waterford Hotel Group and its corporate parent, LMD Holding Company, LLC, are responsible for safeguarding the personal information of their guests. When a company fails to maintain reasonable data security practices and a breach results, affected individuals may be entitled to pursue legal remedies for the harm caused by the exposure of their personal information.

If you have received a notice about this breach, or believe your personal information was compromised as a result of Waterford Hotel Group’s data security incident, you may have legal options. Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Not publicly disclosed
Date of Breach: Not publicly disclosed
Date of Breach: Not publicly disclosed
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.