Hospitality & Tourism — Cyber Threat Activity
Hospitality and tourism is attacked for payment data, guest records and the fact that it cannot close. Our log records more than 360 incidents across 58 countries, over 125 in the trailing 180 days, with 61 groups attributed at least one claim: Qilin (48), Akira (38), Play (29), LockBit (25) and RansomHub (24) lead. Hotels, casinos, restaurant groups and travel operators run high-turnover frontline workforces, franchised estates where security standards vary by owner, and property management, booking and point-of-sale systems that are internet-facing by necessity. An outage is immediately visible to customers, which is precisely why extortion works here: a chain that cannot check guests in negotiates faster than one that merely loses back-office access. The sector is also a favoured target for social-engineering crews who call help desks and talk their way past identity verification rather than exploiting software, a method CISA has documented in detail and which suits an industry where staff churn makes an unfamiliar caller unremarkable. There is a quieter espionage angle as well: state operators have targeted hotel reservation systems to establish where specific individuals were staying and to conduct reconnaissance ahead of official travel, which makes guest data a surveillance asset rather than a fraud commodity. Recorded geography is United States-led at 133 claims, then Spain, the United Kingdom, Canada, France and Australia, a spread that tracks tourism volume rather than any strategic selection. These figures are extortion-site claims rather than confirmed breaches, and card-fraud incidents handled privately through payment brands are largely absent from them.
- Recorded incidents: 499
- Incidents, trailing 180 days: 161
- Tracked threat actors: 86
- Malware families: 75
Recent incidents
- SECOND HOUSE 2026-09-21
- Roan Luxury Camping Holidays 2026-09-18
- Inglewood Golf 2026-09-18
- The Gran Hotel Ingles 2026-09-17
- fchhotels.com 2026-09-17
- Atlas Ocean Voyages 2026-09-14
- Tiflis Palace 2026-09-12
- La Sultana Hotel Group 2026-09-12
- Praveg Caves Jawai 2026-09-12
- Brentwood Country Club 2026-09-08
- TTG Asia Media 2026-09-08
- AbacoViaggi 2026-09-07
- McDonalds Ecuador 2026-09-06
- The Big Table 2026-09-05
- McDonald's Ecuador 2026-09-03
- Royal Plaza On Scotts 2026-09-02
- Reignwood Park Thailand 2026-09-01
- manhattanloft.co.uk 2026-08-31
- Konsumhotel Berghotel Oberhof 2026-08-30
- South Pacific Hotel Limited 2026-08-29
Threat actors targeting Hospitality & Tourism
- Qilin 64 incidents
- Akira 43 incidents
- Play Ransomware 33 incidents
- LockBit 29 incidents
- RansomHub 26 incidents
- DragonForce 24 incidents
- INC Ransom 22 incidents
- SafePay 15 incidents
- Medusa Ransomware 14 incidents
- Lynx Ransomware 13 incidents
- NightSpire 13 incidents
- Stormous 13 incidents
- The Gentlemen 11 incidents
- Cl0p 10 incidents
- Hunters International 7 incidents
- KillSec 7 incidents
- ShinyHunters 6 incidents
- 8Base 5 incidents
- Payload 5 incidents
- Settra 5 incidents
- ShadowByt3$ 5 incidents
- FunkSec 4 incidents
- Krybit 4 incidents
- Meow 4 incidents
Where these victims are
- United States 172
- United Kingdom 26
- Singapore 22
- Spain 21
- Canada 17
- France 16
- Australia 14
- Italy 13
- Germany 12
- India 9
- Mexico 8
- Argentina 6
Malware used against Hospitality & Tourism
Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.
- BlackCat Malware
- Cobalt Strike Malware
- Impacket Tool
- Mimikatz Tool
- PsExec Tool
- REvil Malware
- Ryuk Malware
- AdFind Tool
- Carbanak Malware
- CrackMapExec Tool
- Empire Tool
- LaZagne Tool
Coverage. 94.8% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.