Grand Ion Delemen Hotel Data Breach

Alleged

Ransomware claim involving Grand Ion Delemen Hotel.

Published: Aug 20, 2026 majinahanashi
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Grand Ion Delemen Hotel
Industry
Hospitality
Threat Actor
majinahanashi
Date of Incident
Aug 20, 2026

Executive Summary

Grand Ion Delemen Hotel, a hospitality company located in Malaysia, has been identified as a victim of the Majinahanashi ransomware group. This listing, published on August 20, 2026, was detected by SOCRadar’s Dark Web Monitoring service. Situated in Genting Highlands, Grand Ion Delemen Hotel is a key player in the Southeast Asian tourism market, serving both leisure and business travelers. The targeting of this Malaysian hotel by Majinahanashi highlights the ransomware group’s focus on the Asia-Pacific region’s hospitality sector. Over the 60 days preceding this incident, Majinahanashi claimed 16 other victims, underscoring its active and sustained campaign. The group has shown a significant preference for the global Hospitality industry, particularly targeting hotels and food & beverage establishments in the Asia-Pacific region and the United Kingdom. Recent victims like KT RESTAURANT, BONJOUR GROUP, PIO PIO, and CALICHE share a similar profile with Grand Ion Delemen Hotel. The concentration of Majinahanashi’s attacks in the Asia-Pacific, including Malaysia, suggests a strategic focus on this region as part of its broader hospitality-centric operations.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry related to the grandiondelemen.com domain did not reveal any exposure signals within the sampled data. It is important to note that the absence of such evidence does not confirm the absence of a compromise. This finding simply indicates that no specific credentials related to the queried domain were found in the monitored feeds during the sample period. Majinahanashi is known for its ability to compromise various hospitality organizations across different geographical locations and system architectures, with diverse initial access methods observed across its victim portfolio. The consistent targeting of the hospitality sector by Majinahanashi, particularly in the Asia-Pacific region, should be considered a significant threat indicator for organizations in Malaysia and similar markets. This is true even in the absence of direct stealer-log data for individual entities. Key areas for defense include promptly patching software for remote access and property management systems, mandating multi-factor authentication for all administrative accounts, and closely monitoring for any unusual access patterns to reservation systems, point-of-sale infrastructure, and databases containing guest information.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.