Ransomware victim disclosure
← All victimsTUI UK
Claimed by Snatch · listed 5 years ago
Status timeline
- ListedDec 26, 2021
- Data leakeddate unknown
At a glance
- Group
- Snatch
- Status
- Data leaked
- Country
- United Kingdom
- Sector
- Business Services
- Listed on leak site
- Dec 26, 2021
About the victim
AI dossier — public-source company profileTUI UK is the United Kingdom arm of TUI Group, one of the world's largest travel and tourism companies. It offers package holidays, flights, cruises, and hotel stays, operating through its website, retail stores, mobile app, and a 24/7 TUI Experience Centre staffed by global travel experts. TUI UK serves millions of customers annually across a wide range of leisure travel products.
- Industry
- Travel & Tourism
- Employees
- 10001+
- Founded
- 1923
Attack summary
Severity: high — TUI UK is a major consumer-facing travel company handling significant volumes of customer PII (names, passport details, payment information, booking data). The disclosed status is data_published, confirming exfiltration and publication of data, which constitutes confirmed exfiltration of significant business and likely personal data at scale, even though the exact volume is not specified in the post.The Snatch ransomware group claims to have attacked TUI UK and has disclosed the status as data_published, indicating that exfiltrated data has been published on their leak site. The specific categories and volume of data published are not detailed in the truncated post.
Data the group says was taken
AI dossier — extracted from the leak post- Customer personal data
- Booking and travel records
- Internal business documents
- Contact centre data
What the group claims
When it comes to arranging your holiday, you can click on our website, pop into one of our stores, launch our app or call our contact centre. While you’re away, our 24/7 TUI Experience Centre means our global team of travel experts are on hand
Source
Indexed 5 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

