MarineMax ransomware attack Rhysida

Yesterday, MarineMax, Inc. began notifying 123,494 people of a data breach following a ransomware attack on March 10, 2024. Ransomware group Rhysida claimed the attack, demanding a ransom of 15 bitcoins (worth around $1 million USD at the time) for the stolen data.

The incident caused disruptions to certain areas of the business but these were noted as having been remediated in a SEC filing on April 1. In this filing, the company also confirmed that the hackers had”exfiltrated limited data” and “that includes some customer and employee information, including personally identifiable information.” The type of data involved in the breach has been redacted from the notification. Comparitech has contacted MarineMax for further details.

In the meantime, we highly recommend those affected use the complimentary 24-month membership to Experian’s IdentityWorks that MarineMax is offering.

Who is Rhysida?

Rhysida is thought to have ties to the ransomware group Vice Society and first originated in May 2023. Since then, we have logged 46 confirmed attacks via this group. These attacks have affected nearly 3.5 million records and the average ransom has been just over $1 million.

Rhysida is also the group behind the attack on the British Library in October 2023, the Ann & Robert H. Lurie Children’s Hospital of Chicago in January 2024, and the attack on Hernando County in April 2024.

So far this year we’ve tracked six confirmed attacks via Rhysida and 25 unconfirmed attacks.

Ransomware attacks on retail organizations

So far this year, we’ve tracked 18 ransomware attacks on retail companies across the globe. These have affected 263,821 records, with this attack on MarineMax accounting for most of these.

In 2023, we recorded 57 attacks affecting just over 35.8 million records. Most of these stolen records stem from the December 2023 attack on the VF Corporation (carried out by ALPHV/BlackCat).

The average ransom across these attacks from 2023 to present is nearly $3.9 million.

We have also logged 121 unconfirmed attacks on retail companies this year so far.

More about MarineMax, Inc.

MarineMax is one of the largest retailers of new and used recreational boats and yachts with 78 dealerships and 57 marinas around the world. Its head office is located in Clearwater, Florida.