Ransomware victim disclosure
← All victimsMayfair Hotels & Resorts
Claimed by sinobi · listed 3 months ago
Status timeline
- Listed
Feb 19, 2026
- Data leaked
At a glance
- Group
- sinobi
- Status
- Data leaked
- Country
- India
- Sector
- Hospitality and Tourism
- Listed on leak site
- Feb 19, 2026
About the victim
AI dossier — public-source company profileMAYFAIR Hotels & Resorts is a premier luxury hospitality chain headquartered in Bhubaneswar, Odisha, India, founded in 1982 by Shri Dilip Ray. The group operates over 17 premium properties across India, including resorts in Darjeeling, Gangtok, Goa, Puri, Guwahati, and other locations, blending modern luxury with local cultural heritage. The chain offers accommodations, fine dining, wellness, and event/wedding venues across diverse geographic settings including beaches, mountains, and heritage sites.
- Industry
- Luxury Hospitality & Resorts
- Address
- Bhubaneswar, Odisha, India
- Founded
- 1982
Attack summary
Severity: high — Data has been published (data_published status), indicating confirmed exfiltration. A luxury hotel chain holds significant volumes of guest PII, payment-related records, and corporate data across 17+ properties, making the exposure of meaningful sensitivity and scale.The ransomware group 'sinobi' claims to have attacked Mayfair Hotels & Resorts and has published data (disclosed status: data_published), though the leak post does not specify whether encryption, exfiltration, or both occurred, nor does it state the volume of data involved.
Data the group says was taken
AI dossier — extracted from the leak post- Guest personal information
- Hotel operational records
- Corporate business data
- Employee records
- Reservation and booking data
What the group claims
MAYFAIR Hotels & Resorts is a premier, award-winning luxury hospitality chain in India, founded in 1982 with its headquarters in Bhubaneswar, Odisha. The group operates over 17 premium properties across India, including resorts in Darjeeling, Gangtok, Goa, and Puri, known for blending modern luxury with local heritage
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
