LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Dancenter Listed by alphv Ransomware Group

HIGH severityUnverified claimHow we verify

Dancenter Listed by alphv Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·March 9, 2023
Dancenter Listed by alphv Ransomware Group

Reported March 9, 2023.

HIGH
Severity
March 9, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Dancenter Listed by alphv Ransomware Group (reported March 9, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continued through early 2023 to target mid-sized and large service businesses whose operations depend on customer records and internal systems, often publicising alleged victims on leak sites to apply pressure. Against that backdrop, the Danish holiday-home intermediary Dancenter appeared on a listing attributed to the alphv ransomware group in March 2023. Public detail remains limited; what is known is that the group claimed to have exfiltrated internal files in a ransomware attack, while the number of people affected and the precise contents of any stolen data have not been confirmed in available reporting.

For customers, partners and staff connected to a major booking intermediary, even an unverified claim raises practical questions about exposure and next steps. The following account sticks to the sparse public record and places it in context without speculation.

Breaking down the breach

On or around 9 March 2023, Dancenter was reported as listed by the alphv ransomware group. The available summary states that internal files were exfiltrated in a ransomware attack. No confirmed figure for the number of people affected has been published, nor have technical details of initial access, dwell time, encryption, or any ransom demand been disclosed in the public record. The listing itself constitutes a claim by the group rather than an independently verified confirmation of the full scope of the incident. Beyond the statement that internal files were taken, the precise scale, timeline and method remain undisclosed.

Inside alphv

Alphv, also widely known in public reporting as BlackCat, emerged as a prominent ransomware-as-a-service operation in late 2021. The group has typically operated an affiliate model in which developers supply the ransomware and leak-site infrastructure while affiliates conduct intrusions, exfiltrate data and deploy encryption. Public analyses of prior alphv activity describe double-extortion tactics: data theft followed by threats to publish material if a ransom is not paid, with victims named on a dedicated leak site. The group has been linked in open-source reporting to attacks across multiple sectors and geographies, often using customisable ransomware written in Rust and employing varied initial-access methods such as compromised credentials or exploited vulnerabilities. None of that general pattern should be read as confirmed detail specific to the Dancenter listing; the group’s claim regarding this organisation is limited to the reported assertion of internal-file exfiltration.

Who is Dancenter?

DanCenter A/S is described in the available summary as one of the largest intermediaries of holiday homes in the Danish market. Organisations of this type typically sit between property owners and travellers, managing bookings, availability calendars, payments, customer enquiries and related administrative records. They commonly hold contact details, reservation histories, payment-related information and contractual data belonging both to guests and to homeowners. A breach affecting such an intermediary is consequential because the data sets can span large numbers of individuals and third-party businesses, and because disruption or exposure can affect trust in seasonal and leisure travel services. Public reporting has not established negligence or specific security failures at Dancenter; the known fact is simply the alphv listing and the claim of internal-file exfiltration.

The information in question

The facts name the exposed material only as “internal files exfiltrated in a ransomware attack.” No further breakdown—such as customer databases, financial records, employee files, or authentication credentials—has been disclosed. Organisations that intermediate holiday-home rentals ordinarily process names, addresses, email addresses, phone numbers, booking dates, payment tokens or invoices, and correspondence with property owners. Whether any of those categories were among the files claimed by alphv is unconfirmed. Readers should treat the exact contents as unknown until corroborated by the organisation itself or by independent investigation.

What's at stake

For individuals, the principal risks associated with exposed internal files from a booking intermediary include phishing or social-engineering attempts that reference real reservations, reuse of credentials if any login data were present, and longer-term misuse of contact or identity details. Property owners whose contractual or financial information might appear in internal systems could face similar targeted fraud. For the organisation, consequences can include operational disruption, regulatory notification duties under European data-protection rules, contractual issues with partners, and reputational harm—even when the full extent of data exposure remains unconfirmed. Because the number of people affected is unknown and the data types are only broadly described, the concrete impact cannot yet be quantified from public sources. Calm monitoring of accounts and communications is more useful than assuming the worst.

Were you affected?

If you have booked through Dancenter, own a property listed with the company, or work with it as a partner or employee, treat the March 2023 listing as a prompt to review your exposure rather than as proof that your specific records were taken. Practical first steps include watching for unexpected emails or calls that reference bookings, enabling multi-factor authentication on related accounts, and changing passwords that may have been reused. You can also run a free exposure scan of your email address to check whether it has appeared in known breach data sets. Official statements from Dancenter, if and when issued, remain the authoritative source for confirmation of scope and any recommended actions.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyDancenter security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See Dancenter’s full breach history →

More recent breaches

Ultra Intelligence & Communications Listed by alphv Ransomware GroupDecember 27, 2023sillslegal Listed by alphv Ransomware GroupNovember 27, 2023ASM GLOBAL Listed by alphv Ransomware GroupNovember 13, 2023Okada Manilla Listed by alphv Ransomware GroupNovember 11, 2023

Latest breaches

Read GalaxyWarden’s full analysis of the Dancenter Listed by alphv Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by alphv — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram