Ransomware victim disclosure
← All victimsTUI China
Claimed by Dragonforce · listed 5 hours ago
Status timeline
- ListedAug 3, 2026
- Data leakeddate unknown
At a glance
- Group
- Dragonforce
- Status
- Data leaked
- Country
- China
- Sector
- Hospitality
- Listed on leak site
- Aug 3, 2026
About the victim
AI dossier — public-source company profileTUI China is a joint venture subsidiary of TUI Group, the world's largest leisure tourism operator. Established in late 2003 as the first foreign-majority joint venture in the Chinese tourism industry, it operates travel and tourism services in China.
- Industry
- Tourism & Travel
- Founded
- 2003
Attack summary
Severity: high — Confirmed exfiltration of sensitive PII (passports, visas) and financial/legal business records at scale from a major international tourism operator. Passports and visa data represent regulated personal information affecting potentially thousands of customers.The dragonforce group claims to have exfiltrated passports, visas, internal documentation, and legal and financial documents from TUI China. No encryption or operational disruption is mentioned.
Data the group says was taken
AI dossier — extracted from the leak post- Passports
- Visas
- Internal documentation
- Legal documents
- Financial documents
What the group claims
An affiliate of TUI Group, the world's number one leisure tourism business, TUI China was established in late 2003 as the first joint venture with foreign majority share in the Chinese tourism industry. Passports, visas, internal documentation, legal and financial documents, etc.
Sources
Source
Indexed 5 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

