Royal Plaza On Scotts Data Breach

Alleged

Ransomware claim involving Royal Plaza On Scotts

Published: Sep 2, 2026 Eclipse
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Royal Plaza On Scotts
Industry
Hospitality
Threat Actor
Eclipse
Date of Incident
Sep 2, 2026

Executive Summary

Royal Plaza On Scotts, a hotel located in Singapore known for serving both leisure and corporate guests, was listed on the dark web portal of the Eclipse ransomware group on September 2, 2026. This discovery was made through SOCRadar’s Dark Web Monitoring service. No independent confirmation of a breach has been made at this time. The hotel’s presence on the ransomware group’s portal is particularly noteworthy as it represents the group’s first confirmed targeting of the hospitality sector in Asia-Pacific, suggesting a potential expansion of their operational focus into this region’s critical infrastructure. Eclipse is a relatively new threat actor, and its operational history over the preceding 60 days indicates a focus on a small number of victims. Prior to this listing, Eclipse claimed four victims across the Hospitality, Technology, and Manufacturing sectors, with operations in Italy, India, and Singapore. Notable previous targets include ETNA Software (Italy, Technology), Simplex Engineering (India, Manufacturing), and Moscord (Singapore). The Royal Plaza On Scotts listing marks the second victim attributed to Eclipse in Singapore and the first in the hospitality industry, potentially signaling an increased interest in targeting Asian travel and hotel infrastructure.

Technical Analysis

SOCRadar’s stealer-log telemetry has revealed a significant exposure concerning the domain royalplaza[.]com[.]sg. The analysis uncovered 11 employee credentials associated with organization-controlled systems (Category A). These credentials provide access to critical services including Microsoft 365 tenant access, two distinct Oracle Cloud Identity Service tenants, and the Oracle Hospitality Opera Cloud property management system, which is vital for handling hotel reservations, guest data, and billing. Additionally, 13 records indicate corporate users accessing third-party services (Category C), such as booking distribution channel admin portals and a logistics platform. The compromised credentials were logged between August 25 and September 1, 2026. Notably, 24 of the 25 identified records pertained to only two employees, suggesting a focused compromise rather than a widespread account takeover. The lack of credential rotation within the seven-day freshness window exacerbates the risk posed by this exposure, independent of the ransomware group’s listing. The Eclipse claim heightens the urgency for remediation. Priority actions recommended include forcing an immediate credential reset for the two identified employees. It is also advised to audit sign-in logs for unauthorized sessions across Oracle and Microsoft 365 platforms. Furthermore, a thorough review of Opera Cloud access logs is crucial to detect any suspicious activity related to reservation or guest data export.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.