
MarineMax, one of the world’s largest yacht retailers, has admitted that the sensitive personal information of its customers and employees were compromised as a result of a data security incident in March.
In a filing with the U.S Department of Securities and Exchange Commission (SEC), MarineMax said that on March 10, it identified a cyber security incident where an unauthorised third party gained access to portions of its internal network.
The company, which offers luxury boat, yacht and superyacht services in the U.S., immediately launched an internal investigation, with assistance from third party cyber security experts to determine the nature and scope of the incident and notified relevant law enforcement authorities about the incident.
“Upon detection, the Company initiated its previously determined incident response and business continuity protocols and took immediate measures to contain the incident. As part of this process, the containment measures resulted in some disruption to a portion of the Company’s business,” it said.
MarineMax said that the systems affected by the cyber security incident did not store any sensitive personal data, but the Rhysida ransomware group claimed responsibility for the cyber attack on March 21 and listed the company as a victim on its data leak site.
RHYSIDA #ransomware group has added MarineMax (https://t.co/8uuBXn6yWc) to their victim list. #USA #rhysida #databreach #darkweb #cyberattack pic.twitter.com/RWO9Gyu3HN
— FalconFeeds.io (@FalconFeedsio) March 21, 2024
The group claimed to be in possession of sensitive personal data stolen from the company and threatened to leak it if its ransom demands weren’t met.
In a fresh filing with the SEC, MarineMax said that its investigation has revealed that “a cybercrime organisation accessed a limited portion of our information environment associated with our retail business.”
“As of the date of this filing, our ongoing investigation has identified that this organisation exfiltrated limited data from this environment that includes some customer and employee information, including personally identifiable information,” the company said without revealing how much data was accessed by the ransomware group.
MarineMax said it will notify all affected individuals about the data security incident and provide guidance on how to protect themselves from cyber crimes. It is also working with law enforcement authorities to resolve the situation as soon as possible.
“The Company has incurred, and may continue to incur, certain expenses related to its response to this Incident. Further, the Company remains subject to risks and uncertainties as a result of the Incident,” MarineMax said.
“While the Company is continuing to evaluate the full scope and impact of the Incident, as of the date of this filing, the Incident has not had a material impact on the Company’s operations, and the Company is still in the process of determining whether the Incident is reasonably likely to materially impact the Company’s financial condition or results of operations,” it added.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543