Country Inn & Suites by Radisson Listed by everest Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Country Inn & Suites by Radisson was listed by the everest ransomware group on October 19, 2024, after internal files were exfiltrated in a ransomware attack that affected an undisclosed number of people. Individuals who may have been impacted are advised to review the notice and take protective steps.
On 19 October 2024, the ransomware group known as everest listed Country Inn & Suites by Radisson on its leak site, claiming it had exfiltrated internal files in a ransomware attack. The number of people affected remains unknown. For guests, past guests, and anyone whose contact or payment details may sit in hotel systems, the practical stakes are straightforward: personal information and booking records, if exposed, can be used for fraud, identity misuse, or targeted scams long after a stay ends.
Public detail is limited to the group’s listing and its accompanying claims. No independent confirmation of the scale, method, or exact contents has been provided in the available record. What follows sets out what is known, what the group asserts, and what people can usefully do next.
Inside the incident
According to the reported listing dated 19 October 2024, everest claims to have carried out a ransomware attack against Country Inn & Suites by Radisson and to have exfiltrated internal files. The group’s own summary asserts that the material includes “thousands and thousands of client’s personal information, credit cards info, internal emails, incidents, messages,” a “full calendar of past and future bookings,” and other internal material. It further claims evidence of poor password and private-data handling and states that management was aware of events and had not acted; it demands that the company follow its instructions before a timer ends.
The available facts do not disclose how the attackers gained access, when the intrusion began or ended, whether systems were encrypted, whether a ransom was paid, or how many individuals are involved. The count of people affected is unknown. The listing itself is a claim by the group; it has not been independently verified in the material provided. Timing beyond the 19 October 2024 report date, technical method, and precise volume of data remain undisclosed.
Who is everest?
Everest is a ransomware operation that has appeared in public reporting as a double-extortion group: it typically claims to encrypt systems while also stealing data and threatening to publish it on a dedicated leak site if its demands are not met. Like other groups of this type, it posts victim names and sample descriptions to pressure organisations and to advertise its activity. Its listings are claims made by the actors themselves; they are not independent audits of what was taken or how.
Public knowledge of everest centres on this pattern of naming organisations, describing stolen material in broad terms, and setting deadlines. Nothing in the facts for this incident confirms that everest’s specific assertions about Country Inn & Suites by Radisson—volume of personal data, credit-card details, booking calendars, or internal awareness—are accurate. Those statements should be read as the group’s unverified claims.
About Country Inn & Suites by Radisson
Country Inn & Suites by Radisson is a hotel brand operating within the hospitality sector. Properties under such brands typically manage guest reservations, contact details, payment information for stays and incidentals, loyalty or membership records where applicable, and internal operational data such as staff communications, incident logs, and booking calendars. Hotels sit at the intersection of travel, payments, and personal identity: guests routinely hand over names, addresses, phone numbers, email addresses, and card data in order to book and check in.
A breach affecting a hotel brand is consequential because the same systems that enable smooth stays also concentrate sensitive personal and financial information. Even when the exact scope of an incident is unconfirmed, the sector’s data holdings mean that any credible claim of exfiltration raises legitimate concern for people who have stayed, booked, or otherwise interacted with the brand.
What data was at risk
The facts name the exposed material only as “internal files exfiltrated in ransomware attack.” The everest listing claims far more: large volumes of clients’ personal information, credit-card information, internal emails, incidents, messages, and a full calendar of past and future bookings, along with assertions about password storage and management awareness. Those additional details are the group’s claims; they are not independently confirmed in the available record.
Organisations of this kind typically hold guest identity and contact data, payment-card or tokenised payment information, reservation histories, and internal correspondence. Whether any or all of those categories were in fact taken in this incident is unconfirmed. Exact contents, file counts, and the number of affected individuals remain undisclosed. Readers should treat the group’s descriptive list as an allegation, not as verified inventory.
Why it matters
If personal and payment data were among the files taken, affected people face concrete risks: fraudulent charges, account takeover attempts that reuse exposed emails or phone numbers, phishing that references real bookings or stays, and longer-term identity misuse. Booking calendars, if exposed, could reveal travel patterns and contact points that scammers exploit. Internal emails and incident records can also aid social-engineering attacks against staff or partners.
For the organisation, a ransomware claim of this type brings operational disruption, potential regulatory scrutiny, reputational harm, and the cost of investigation and remediation—regardless of whether every claim on a leak site is later substantiated. Because the number of people affected is unknown and the precise data types are unconfirmed beyond “internal files,” the full real-world impact cannot yet be measured. That uncertainty itself is a reason for caution rather than panic: people who have dealt with the brand should assume their information might be involved until clearer official information appears, and should take proportionate protective steps.
What to do if you're exposed
If you have stayed at, booked with, or otherwise shared details with Country Inn & Suites by Radisson, treat the listing as a prompt to check your own exposure rather than as proof that your specific records were taken. Monitor bank and card statements for unfamiliar charges and consider requesting a new card if you used one for hotel payments. Be sceptical of unexpected emails or calls that reference a stay, booking, or “security issue” and that ask for passwords, codes, or further personal data. Review account passwords that may have been reused and enable multi-factor authentication where available. Keep records of any suspicious contact.
You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. That check does not confirm or rule out involvement in this specific incident, but it can surface other exposures that deserve attention. Official notifications from the company or from regulators, if and when they arrive, should take priority over claims posted by threat actors. Stay measured, verify sources, and act on concrete signs of misuse rather than on unverified leak-site language alone.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Total Patient Care LLC;A Sensitive Touch Home Health;Alphastar Home Health Care;Heart of T Listed by everest Ransomware GroupArtistic Family Dental;Value Dental Center;Sparkling Smiles Family Dentistry Listed by everest Ransomware GroupA Sensitive Touch Home Health;Alphastar Home Health Care;Heart of Texas Home Healthcare Se Listed by everest Ransomware GroupMCNA Dental 1 million patients records Listed by everest Ransomware GroupLatest breaches
Publicly posted by everest — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.