Data breach
Pyramid Global Hospitality
- Records
- 58,175
- Breach date
- 23 September 2025Estimated
- Added
- 29 September 2025
What was exposed
5 types of data · 4 more reported · 1 puts you at serious risk
- Email addresses1
- Names1
- Home addresses1
- Phone numbers1
- Social security numbers1
- Driving licence numbersReported, not counted
- Bank account numbersReported, not counted
- Insurance detailsReported, not counted
- Medical recordsReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Pyramid Global Hospitality, a Boston-based hotel and resort management company, suffered a data breach that exposed personal information belonging to current and former employees. According to a filing with the Maine Attorney General, the breach occurred on August 13, 2025, and the company discovered suspicious activity on its network on or about August 14, 2025. The incident later gained wider attention in late September 2025, when the WorldLeaks ransomware group listed the company on its leak site and leaked archives began circulating online. The investigation team indexed 58,175 rows of data from the leak, added to its database on September 29, 2025. The company has begun mailing notification letters to affected individuals and is offering credit monitoring services.
Breach Timeline
August 13, 2025: The breach occurred, according to the company's filing with the Maine Attorney General.
August 14, 2025: Pyramid Global Hospitality discovered suspicious activity on its computer network and launched an investigation with third-party consultants.
September 25, 2025: Breach monitoring platforms began listing the incident, which was claimed by the WorldLeaks ransomware group.
October 29, 2025: The company began sending written notification letters to affected individuals, per the Maine Attorney General filing.
February 25, 2026: The company reported the breach to the California Attorney General's office.
February 27, 2026: The law firm Edelson Lechtzin LLP announced it was investigating claims on behalf of affected individuals.
What Information Was Compromised?
Our analysis found the following data types in this breach: Social Security numbers, names, home addresses, email addresses, and phone numbers.
The company's notification letters, as summarized by Edelson Lechtzin LLP, indicate the affected files may have also contained driver's license numbers, financial account information, health insurance information, and medical information belonging to current and former employees.
Not every individual is affected by every type of data listed here.
The presence of Social Security numbers and employment-related records suggests the breach centered on employee and contractor data rather than hotel guest records. The Maine Attorney General filing lists 1,299 affected Maine residents; a total national count was not listed in that filing.
What Are the Potential Risks for Affected Individuals?
The combination of Social Security numbers, addresses, and contact details carries a high risk of identity theft. Affected individuals could face tax refund fraud, in which criminals file fraudulent returns using stolen SSNs, as well as fraudulent unemployment benefit claims opened in their names. Financial account information, if exposed, raises the possibility of unauthorized account activity. Medical and health insurance details can enable medical identity fraud, which is often harder to detect than ordinary financial fraud. Stolen names and contact information can also fuel targeted phishing attempts that impersonate employers, banks, or healthcare providers.
What Is Pyramid Global Hospitality Doing in Response?
The company launched an investigation with the help of third-party consultants and began mailing written notification letters to affected individuals on October 29, 2025, according to the Maine Attorney General filing. It is offering 12 months of credit monitoring and identity protection services through IDX. The company reported the breach to state attorneys general in Maine and California in February 2026. In February 2026, Edelson Lechtzin LLP announced it was investigating potential class action claims against the company. The company's filing describes the incident as an external system breach involving hacking.
What Should You Do If You Were Affected?
If you receive a notification letter from Pyramid Global Hospitality, enroll in the offered IDX credit monitoring and identity protection services, which run for 12 months. Review your credit reports from all three major bureaus for accounts or inquiries you do not recognize. Monitor your bank and financial account statements regularly, and consider placing a fraud alert or a security freeze on your credit files. Watch for phishing emails that reference your employer or personal details, and file your tax returns early to reduce the risk of a fraudulent return being submitted in your name. If you see signs of identity theft, report it to the Federal Trade Commission at IdentityTheft.gov.
In the news
- Maine Attorney General Data Breach Notification filingmaine.gov (opens in a new tab)
- California Attorney General breach notification sampleoag.ca.gov (opens in a new tab)
- PRNewswire: Edelson Lechtzin LLP data breach alertprnewswire.com (opens in a new tab)
- BreachSense: Pyramid Global Hospitality Data Breachbreachsense.com (opens in a new tab)
