LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Disneyland Paris Listed by anubis Ransomware Group

HIGH severityUnverified claimHow we verify

Disneyland Paris Listed by anubis Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·June 20, 2025
Disneyland Paris Listed by anubis Ransomware Group

Reported June 20, 2025.

HIGH
Severity
June 20, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Disneyland Paris was listed by the anubis ransomware group on June 20, 2025, with internal files reported as exfiltrated. Individuals who may have had dealings with the resort should review their accounts and consider changing passwords or enabling additional security measures.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

People who have visited Disneyland Paris, worked there, or done business with the resort may now face uncertainty about whether their personal or professional information has been exposed. On 20 June 2025 the organisation was listed by the ransomware group anubis, which claims to have taken confidential internal files. The number of people affected remains unknown, and public detail about exactly what left the network is limited. For anyone whose details might be among those files, the practical stakes are clear: possible misuse of personal data, unwanted contact, or identity-related fraud, even if the full scope is still unconfirmed.

This article sets out only what has been reported, places the claim in context, and outlines the concrete risks and first steps people can take while more information is awaited.

What happened

On 20 June 2025 Disneyland Paris was listed by the anubis ransomware group. According to the group’s claim, internal files were exfiltrated during a ransomware attack and the material consists of confidential Disneyland documents. No further public detail has been released about the date of the intrusion, the method used, the volume of data taken, or whether any systems were encrypted. The number of people affected is unknown. The listing itself is an unverified claim by the group; independent confirmation of the breach or of the precise contents of the files has not been made public.

Who is anubis?

Anubis is a ransomware operation that has appeared on public leak sites in recent years. Like many contemporary ransomware groups, it typically follows a double-extortion model: data is stolen before systems are encrypted, and the threat of public release is used to pressure the victim. The group posts victim names and sample files on dedicated leak sites to demonstrate access and to increase leverage. Its listings are claims of successful intrusion and data theft; they are not independent verification. Prior public activity associated with anubis has involved a range of commercial and organisational targets, but no specific statements by the group about Disneyland Paris beyond the listing itself are part of the public record for this incident.

Disneyland Paris and its sector

Disneyland Paris is a major European theme-park and resort complex operated by a subsidiary of The Walt Disney Company. It welcomes millions of visitors each year and employs a large permanent and seasonal workforce. Organisations of this kind routinely hold customer booking and payment records, loyalty-programme data, employee personnel files, contractor details, and internal operational documents. A ransomware claim against such an operator is consequential because the volume and sensitivity of the data typically stored create both individual privacy risks and operational disruption risks for the business. Public detail does not establish how far any of those categories were involved in the claimed incident.

What data was at risk

The only description provided is that internal files were allegedly exfiltrated and that the material consists of confidential Disneyland documents. Exact data types, file counts, and whether customer, employee or partner records were included have not been disclosed. Organisations in the leisure and hospitality sector commonly retain names, contact details, payment information, passport or identity data for certain bookings, employment records, and internal correspondence. Because none of those categories has been confirmed as present in the claimed exfiltration, it remains unconfirmed what, if any, personal data of visitors or staff was among the files. Readers should treat the precise contents as unknown until further official information appears.

What's at stake

For individuals, the main risks are the possible misuse of any personal details that may have been taken—phishing attempts that appear more credible, identity fraud, or unsolicited contact. Because the scale and exact contents remain undisclosed, it is not possible to quantify how many people face those risks or how severe they are. For the organisation, a ransomware claim can disrupt operations, damage trust, and trigger regulatory scrutiny under European data-protection rules, regardless of whether the full extent of any data loss is later confirmed. Both the human and organisational consequences therefore hinge on details that are still public only as an unverified group claim.

What to do if you're exposed

If you have visited, worked at, or supplied services to Disneyland Paris and are concerned your information may have been involved, take a few measured steps. Monitor bank and card statements for unexpected activity and enable multi-factor authentication on important accounts. Be cautious of unsolicited emails or messages that reference the park or claim to offer compensation or security updates. Consider placing a fraud alert with credit-reference agencies if you live in a jurisdiction that offers that service. You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets; such a scan will not confirm or rule out involvement in this specific incident, but it can show whether your address has surfaced elsewhere. Official statements from Disneyland Paris or relevant authorities remain the most reliable source of further guidance as more information becomes available.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyDisneyland Paris security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Disneyland Paris’s full breach history →

More recent breaches

Fun For Less Tours Listed by anubis Ransomware GroupDecember 1, 2025Two Kings Casino Resort Listed by anubis Ransomware GroupApril 23, 2025FÉTIS Group & SECOM Engineering Listed by anubis Ransomware GroupJune 11, 2026A.R.Ge.Co Listed by anubis Ransomware GroupMay 13, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Disneyland Paris Listed by anubis Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by anubis — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram