Ransomware crews hit Southeast Asian hotels, not hospitals

Ransomware crews working across Southeast Asia are picking noticeably different targets than they do elsewhere in the world. Over the last 90 days, hotels, resorts and travel operators accounted for roughly one in fourteen of the region's named victims, close to three times their share of ransomware listings everywhere else. Hospitals, the sector that dominates ransomware coverage in the United States and Europe, barely feature at all.

The figures come from IntelFusions' own tracking of ransomware extortion listings. In the 90 days to 9 August 2026 we recorded 132 claims against organizations in eight Southeast Asian countries, naming about 130 distinct victims, posted by 34 different crews. Singapore drew the most listings (34), followed by Thailand (27), Malaysia (22), Indonesia (16), the Philippines (15) and Vietnam (14).

What the victim mix looks like

Sorting those victims by sector produces a profile that does not match the global picture:

Recent hospitality listings include the Katathani Phuket Beach Resort in Thailand, named by the DragonForce crew on 27 July, and the Furama Bukit Bintang hotel in Kuala Lumpur, named by NightSpire the same day. Others include the Malaysian conglomerate Sunway Berhad, whose businesses span hotels and theme parks, and Red Planet Hotels in the Philippines. In May a crew also listed Hotelogix, a Singapore-based property management platform used by smaller independent hotels, the kind of supplier whose compromise reaches well past a single property.

Why hotels

Nothing in the listings explains the crews' reasoning, so any read here is inference rather than established fact. Two things plausibly matter. Tourism is a far larger slice of the Thai, Malaysian and Philippine economies than it is of most Western ones, so there are simply more hotel groups to hit. Hotels are also attractive on the merits: they hold passport scans, payment card data and guest records, they cannot easily absorb downtime in peak season, and mid-sized chains often stretch a small IT team across many properties.

The region's hotels have drawn other kinds of attention too. In June, researchers documented a remote access trojan aimed at Japanese hotels that hid its command channel on the TON blockchain. The contrast with the United States is sharp, where crews piled onto healthcare providers over the July 4 weekend.

Treat the numbers with care

These are unverified extortion claims posted by the gangs themselves, not confirmed breaches, and several of the organizations named have never publicly acknowledged an incident. The sector counts are small: the hospitality figure rests on nine listings. Roughly two thirds of Southeast Asian listings carry no usable sector label at all, so the mix should be read as indicative rather than settled. One Malaysian entity was posted three times in as many weeks, a reminder that raw listing counts overstate the number of distinct victims.

What operators should do

For hotel groups and their technology suppliers, the useful steps are unglamorous. Enforce phishing-resistant multi-factor authentication on remote access and management consoles. Keep offline backups of property management and reservation systems, and rehearse restoring them. Segment guest-facing networks from corporate ones. Press suppliers for their own incident response commitments, because a booking or property management platform is a single point of failure for every property it serves. Regional response bodies including Malaysia's MyCERT and Thailand's ThaiCERT accept incident reports and publish sector advisories.

This briefing is provided by IntelFusions for informational and defensive purposes only. It summarizes extortion claims published by ransomware leak sites. Those claims are made by the attackers, are unverified, and may be false, exaggerated, or recycled from earlier breaches. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions