Ransomware victim disclosure
← All victimsHILTON.COM
Claimed by Clop · listed 5 months ago
Status timeline
- ListedJan 25, 2026
- Data leakeddate unknown
At a glance
- Group
- Clop
- Status
- Data leaked
- Country
- United States
- Sector
- Hospitality and Tourism
- Listed on leak site
- Jan 25, 2026
About the victim
AI dossier — public-source company profileHilton Worldwide Holdings Inc. operates a global hospitality platform with over 6,100 properties across 119 countries under multiple brands including Hilton Hotels & Resorts, Waldorf Astoria, and Conrad Hotels & Resorts, offering luxury resorts, full-service hotels, and extended-stay accommodations.
- Industry
- Hospitality and Tourism
Attack summary
Severity: high — Confirmed data publication by ransomware group targeting major hospitality platform with millions of customer records at scale; guest PII and payment information likely exposed.Clop group claims to have compromised Hilton.com and published data; specifics of exfiltration scope or encryption status are not detailed in the available leak post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- user booking records
- customer contact information
- payment/reservation data
Original description
AI-summarised, not from the leak postHilton.com is the official online platform for Hilton Worldwide Holdings Inc., a global hospitality company. The site allows users to book rooms in more than 6,100 properties across 119 countries. These properties include luxury resorts, full-service hotels, and extended-stay suites from various Hilton brands such as Hilton Hotels & Resorts, Waldorf Astoria Hotels & Resorts, Conrad Hotels & Resorts, and more.
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

