Holiday Inn Vilnius Data Breach

Alleged

Ransomware claim involving Holiday Inn Vilnius.

Published: Sep 28, 2026 SafePay
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Holiday Inn Vilnius
Industry
Hospitality
Threat Actor
SafePay
Date of Incident
Sep 28, 2026

Executive Summary

The Holiday Inn Vilnius, a property operating under the IHG Hotels & Resorts brand in Lithuania’s capital, has been listed on the Safepay ransomware group’s dark web portal as of September 28, 2026. This incident was identified through SOCRadar’s Dark Web Monitoring. A listing for a branded hotel property carries significant implications, potentially extending beyond the individual location to encompass franchise infrastructure, shared booking systems, and loyalty platform data. Safepay has claimed approximately 40 victims over the last 60 days, with core sectors including Manufacturing, Agriculture and Food Production, and Others. The primary geographies targeted by Safepay are the United States, Switzerland, and Spain. While Lithuania is not among Safepay’s most frequently targeted countries, the group has demonstrated a steady expansion of its reach within Europe. Recent European victims listed by Safepay include E.A. Groep (Netherlands), Sumperk (Czech Republic), and Bio-Strath AG (Switzerland).

Technical Analysis

A SOCRadar stealer-log query conducted against the Holiday Inn Vilnius domain returned no records. However, it is important to note that third-party booking platforms and the use of personal staff email aliases, which are common in the hospitality sector, might be outside the scope of this particular query. Therefore, the absence of records does not conclusively indicate that the organization is unaffected by credential compromise. The potential for compromise through credentials harvested by infostealers is a significant concern, as these can provide threat actors with access to corporate accounts and remote-access portals. For a franchised property like Holiday Inn Vilnius, this complexity is heightened. A ransomware intrusion could be isolated to local systems or potentially intersect with centralized platforms managed by the parent brand, IHG. This ambiguity poses operational challenges for IHG’s security teams, and the current listing does not resolve this uncertainty. For IHG and Holiday Inn’s security operations, this listing serves as a signal to investigate at the property level to determine if shared infrastructure is implicated. Travelers whose booking data may be associated with this property are advised that while no immediate action is required, awareness of potential data exposure is warranted. Further dark web monitoring and proactive credential hygiene checks, including password rotation and multi-factor authentication review, are recommended.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.