Ransomware victim disclosure
← All victimsDTH Travel
listed as Dithelm Travel Group · Claimed by Global · listed 1 year ago
Status timeline
- ListedJul 26, 2025
- Data leakeddate unknown
At a glance
- Group
- Global
- Status
- Data leaked
- Country
- Thailand
- Sector
- Hospitality and Tourism
- Listed on leak site
- Jul 26, 2025
About the victim
AI dossier — public-source company profileDTH Travel (formerly Diethelm Travel) is a destination management company (DMC) based in Asia with multiple offices across the continent. They specialize in tailor-made, responsible and authentic travel experiences including holiday packages, excursions, and MICE (Meetings, Incentives, Conferences, Exhibitions) services with a boutique, locally grounded approach.
- Industry
- Destination Management & Travel Services
Attack summary
Severity: medium — Data has been published by the threat actor (disclosed_status confirms 'data_published'), indicating confirmed exfiltration. However, no specific sensitive data categories or proof files are detailed in the available excerpt, and no operational impact is stated.The ransomware group claims to have compromised DTH Travel and published data. The specific nature of the compromise (encryption, exfiltration, or both) and the extent of data exposure are not detailed in the available post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- business records
- client information
- operational data
What the group claims
The travel agency formerly known as Diethelm Travel, now operating as DTH Travel, is a destination management company (DMC) based in Asia with multiple offices across the continent. They specialize in tailor-made, responsible and authentic travel experiences, covering holiday packages, excursions, MICE and more, with a boutique, locally grounded service approach
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

