Quick Summary
AllegedExecutive Summary
SOCRadar’s Dark Web Monitoring identified a listing of Atlas Ocean Voyages on September 14, 2026, by the Booba Project ransomware group. Prior to this listing, credential data from the company’s partner-facing web systems had been circulating in criminal markets for at least six months. This dual finding presents a significant risk to both customer and travel-partner data. Atlas Ocean Voyages, a luxury cruise operator based in the United States, collaborates extensively with travel agencies across North America. Its operational model, which involves numerous partners and customer interactions through web portals, makes it a potential target for ransomware and data extortion activities. The Booba Project has claimed at least 10 other victims within the past 60 days, including Mestechkin Law Group P.C., Country-Wide Insurance, Betz Industries, and Incredible Technologies, all based in the US. The group’s targeting primarily focuses on US-based entities, with additional activity noted in Mexico and Russia. The listing of Atlas Ocean Voyages marks the group’s first identified victim in the hospitality sector within this observation period. This pattern suggests a broad approach to targeting, leveraging exposed credentials across various industries.
Technical Analysis
Stealer-log analysis for atlasoceanvoyages[.]com yielded 25 records. These records were distributed across the primary domain, a travel-advisor subdomain (atlasadvisors), and a customer self-service portal (myatlas subdomain). Of the 25 records, 18 were attributed to external users, likely travel partners and customers, rather than corporate employees, with the remaining 7 records being unclear. The observed data freshness window for these credentials ranges from March 10 to August 29, 2026. This telemetry indicates a risk profile centered on customer account takeover and potential compromise of supplier access. Two specific endpoints warrant attention. Firstly, the WordPress admin login on the travel-advisor subdomain exhibited four credential records spanning from March to August 2026. This six-month window suggests either persistent reinfection of a partner’s device or a failure to rotate credentials, potentially providing an attacker with an entry point to partner data and deeper infrastructure access. Secondly, the customer portal on the myatlas subdomain showed repeated credential activity from the same external usernames across multiple months, indicating sustained exposure rather than a isolated incident. Ransomware operators, including the Booba Project, commonly leverage validated partner-portal or admin credentials for initial access. A compromised WordPress admin account on a partner-facing subdomain can serve as a staging point that bypasses traditional corporate network security controls. The prolonged exposure of credentials for both partner and customer portals indicates a significant risk for unauthorized access, potential data exfiltration, and subsequent ransomware deployment. Immediate actions should include rotating all WordPress admin credentials on the atlasadvisors subdomain, forcing re-authentication on the myatlas customer portal, and conducting an audit of partner account activity from March through August 2026 for any unauthorized access.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.