BLISS 1041 Data Breach

Alleged

Ransomware claim involving BLISS 1041

Published: Aug 30, 2026 Qilin
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
BLISS 1041
Industry
Hospitality
Threat Actor
Qilin
Date of Incident
Aug 30, 2026

Executive Summary

The ransomware group qilin has claimed BLISS 1041, a hospitality organization based in Malta, as a victim. The claim was made on August 30, 2026, with the threat actor asserting unauthorized access to the company’s systems and data. This listing is supported by infostealer telemetry that captured employee credentials for a Box tenant and a third-party GitHub corporate account. These credentials were obtained across a period from January 7, 2026, to August 13, 2026, indicating a significant window of potential access prior to the public claim. No independent verification of the breach details has been completed at this time. In the 60 days preceding this report, qilin has claimed a substantial number of victims, totaling 248. The group’s primary targets geographically are the United States and Germany, with a strong focus on the Manufacturing and Professional Services sectors. The inclusion of BLISS 1041, a hospitality entity in Malta, suggests an expansion of qilin’s targeting beyond its typical core sectors and operating regions, indicating a consistent high volume of attacks.

Technical Analysis

SOCRadar CTI’s analysis of stealer-log data revealed a “severe_exposure_in_sample” verdict for BLISS 1041. The telemetry identified two employee credentials associated with a Box tenant and one GitHub corporate third-party credential. These credentials were captured within a timeframe spanning January 7, 2026, to August 13, 2026, indicating a seven-month period of credential exposure prior to the threat actor’s listing. This exposure spans access points for cloud storage and code repositories. The capture of these credentials suggests a potential pathway for unauthorized access. Infostealer malware can harvest credentials from various sources, which threat actors can then leverage for initial access into corporate networks. While this telemetry does not definitively confirm that BLISS 1041 was compromised via these specific credentials, it highlights a significant risk that could have facilitated the intrusion claimed by qilin. The ongoing monitoring of stealer logs is crucial for identifying such exposures. The observed credential exposure for BLISS 1041, encompassing cloud storage and code repository access, warrants immediate attention. Organizations should consider continued dark web and stealer-log monitoring to detect any further exposed credentials. Proactive credential hygiene, including regular password rotation and a thorough review of multi-factor authentication configurations, is highly recommended. Additionally, reviewing access logs for Microsoft 365, VPNs, and other remote access portals can help identify any suspicious activity.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.