TUI China Data Breach

Alleged

Ransomware claim involving TUI China.

Published: Aug 3, 2026 DragonForce
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
TUI China
Industry
Business Services
Threat Actor
DragonForce
Date of Incident
Aug 3, 2026

Executive Summary

TUI China, a hospitality company operating in China, has been identified as a victim by the DragonForce ransomware group. The listing appeared on the group’s dark web portal on August 3, 2026, and was detected by SOCRadar’s Dark Web Monitoring service. The company’s presence in the hospitality sector within China makes it a potential target for ransomware operations. This incident is notable as DragonForce added two Chinese organizations to its portal on the same day, aligning with a recent increase in listings targeting entities in the Asia-Pacific region. Over the 60 days preceding this listing, DragonForce claimed 46 other victims. The ransomware group’s targeting trends show a significant focus on the Business Services, Manufacturing, and Technology sectors. Its primary victim countries include the United States, the United Kingdom, and the United Arab Emirates, with China and Hong Kong also being frequently targeted. TUI China’s situation aligns with the group’s recent activity in the Asia-Pacific region, although the hospitality sector is secondary to DragonForce’s preferred verticals of business services and manufacturing. Other hospitality or China-based companies recently listed by DragonForce include Katathani Phuket Beach Resort, Atcom, Road Ahead Technologies Consultant, and MBM Law.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry identified a single record associated with the tui.cn domain. However, the classification of this record is limited and does not provide conclusive evidence of a compromise. The recovered credential was linked to a URL with an administrative-looking login path, indicating potential back-office or privileged access. The username was masked, making it impossible to determine if the account belonged to an employee or an external entity. Consequently, this record falls into an unclassified category, as it does not contain confirmed employee, customer, or third-party-service information. The overall assessment for this entry was insufficient data. The recorded timestamp for this credential is from February 2026, approximately six months prior to the DragonForce listing. It is important to note that this is a single-record sample from a paginated response, and therefore, it neither confirms nor rules out broader data exposure. For ransomware groups like DragonForce, credentials harvested by infostealers are a recognized method for initial access. Threat actors or

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.