Getting a letter in late July telling you that your Social Security number was stolen in November of the previous year is a little unsettling. The Biddeford woman Erica Cote was in that situation when Maine Course Hospitality Group sent out breach notification letters dated July 31, which was almost nine months after the event, which took place on November 1, 2025. The damage had already been done, and the ransomware group behind it was well known on the dark web.
Now, Cote has sued in U.S. District Court in Portland as part of a class action, and it’s easy to see why. The breach affected a total of 7,194 people, including almost 4,000 people who live in Maine. Not only names and email addresses were made public. Bad people got access to health records, Social Security numbers, and ID numbers issued by the government, according to investigators. You know what? That kind of information can ruin someone’s money for years.
The Maine Course Hospitality Group is a company based in Freeport that runs about twenty hotels in New England and a few more in Florida and North Carolina. There are Courtyards near Portland International Airport, Hampton Inns in Waterville, Bath, and Augusta, and other Hilton and Marriott hotels. Most guests probably never gave much thot to what happens to the personal information they give at check-in. That’s not a bad thing about the guests. It seems likely that a medium-sized regional hotel chain has basic safety measures in place. The lawsuit says it doesn’t seem to have.
A ransomware group called Qilin claimed responsibility for the breach in a blog post that seemed like a threat: Maine Course had to release a “full dump of sensitive data” right away or they would be in touch with them. In early November 2025, that post showed up on the dark web. It looks like the company told the Maine Attorney General about the breach on July 31, 2026. There is a big space between those two dates.

Maine law says that breach notices must be sent “without delay.” For ongoing criminal investigations, notices can be put off if they would make it harder to gather evidence, but the law still says they should be sent within seven days of law enforcement clearing it. Still, it’s not clear what happened from November to July. Maine Course is being sued because it “unreasonably delayed” telling victims and didn’t put in place “reasonable security protections” from the start. The second part is important. You can argue about the time frame. If a company collects Social Security numbers and health records as part of doing business, it’s harder to say that they don’t have to keep them safe.
It’s still not clear if Cote and the other possible class members were hotel guests, employes, or partners in business. It’s interesting how vague that is. This suggests that the breach may have affected more than one part of the business, not just the system for making reservations for guests. Lawyers for both sides haven’t said anything in public, and it hasn’t been confirmed what exactly Qilin got.
It is clear that the lawsuit wants to create a class, have a trial by a jury, and get money damages. The breach is being looked into by a number of law firms, including the national class-action firm Edelson Lechtzin LLP. As more people learn about this case, it’s possible that it will get more plaintiffs, especially from the 4,000 or so Maine residents who may not fully understand what this kind of exposure means in the long run.
People’s names, credit card numbers, travel habits, and information from loyalty programs have always been important in the hospitality business. But government IDs and health records are not the same. They are in a group that is more at risk. It’s not just morally right for a company that collects that kind of information to keep it safe. In Maine, it’s okay to do. This lawsuit, which was filed in secret in federal court in Portland, might make that point clear in a way that the business world won’t forget any time soon.

