Ransomware victim disclosure
← All victimsHyatt Place New York / Chelsea Hotel
Claimed by Nightspire · listed 5 months ago
Status timeline
- ListedJan 14, 2026
- Data leakeddate unknown
At a glance
- Group
- Nightspire
- Status
- Data leaked
- Country
- United States
- Sector
- Hospitality and Tourism
- Listed on leak site
- Jan 14, 2026
About the victim
AI dossier — public-source company profileHyatt Place New York / Chelsea is a hotel property operating under the Hyatt Place brand, located in the Chelsea neighborhood of New York City, New York. It is part of the broader Hyatt Hotels Corporation portfolio and caters to business and leisure travellers. As a property-level operation it handles guest reservations, payment data, and personal information for hotel guests.
- Industry
- Hospitality & Hotel Management
- Address
- Hyatt Place New York / Chelsea, New York, NY, United States
Attack summary
Severity: medium — The disclosure status is 'data_published', indicating some data has been released, which elevates severity beyond low. However, no data inventory, file count, or specifics about the nature of the exfiltrated data (e.g., guest PII, payment card data) are provided in the post, preventing a higher classification. Hotel operations typically involve regulated PII and payment data, but this cannot be confirmed from available evidence.The Nightspire ransomware group claims to have attacked Hyatt Place New York / Chelsea Hotel and has disclosed data, though the leak post provides minimal detail on whether encryption, exfiltration, or both occurred. No ransom amount or data volume was stated.
What the group claims
Hyatt Place New York / Chelsea Hotel
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

