Konsumhotel Berghotel Oberhof Data Breach

Alleged

Ransomware claim involving Konsumhotel Berghotel Oberhof

Published: Aug 30, 2026
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Konsumhotel Berghotel Oberhof
Industry
Hospitality
Date of Incident
Aug 30, 2026

Executive Summary

ZaWoo ransomware group listed Konsumhotel Berghotel Oberhof as a claimed victim on 2026-08-30. This incident represents a risk signal for any organization with supplier or guest-data ties to this German hospitality firm. The threat actor published the listing on its leak site, alleging unauthorized access to the company’s systems and data. It is important to note that no independent verification has been completed, and the listing remains an unconfirmed claim. ZaWoo has claimed 16 victims in the past 60 days. Their primary targeting has been concentrated in Germany and Austria, with a focus on the Technology and Manufacturing industries. Konsumhotel Berghotel Oberhof, with the domain berghotel-oberhof[.]de, falls within the group’s established geographic focus. ZaWoo appears to operate with a smaller, more targeted victim set rather than engaging in broad-volume campaigns.

Technical Analysis

SOCRadar CTI’s stealer-log analysis returned a “no_exposure_in_sample” verdict for Konsumhotel Berghotel Oberhof. This means that no credential records directly tied to berghotel-oberhof[.]de were found within the current infostealer datasets that were queried. However, a null result from this specific analysis does not entirely clear the claim made by the ZaWoo group. Phishing campaigns or the exploitation of exposed remote-access services remain plausible initial-access paths, especially given ZaWoo’s known tactics, techniques, and procedures (TTPs). Continued monitoring of dark web forums and stealer-log feeds is recommended, alongside proactive credential hygiene checks, password rotation, and multi-factor authentication reviews for associated accounts.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.