gettys.com Listed by qilin Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
gettys.com was listed by the qilin ransomware group on February 28, 2025, after internal files were exfiltrated in a ransomware attack. The number of people affected is undisclosed; individuals are advised to check whether their information may have been exposed and to take appropriate protective steps.
When a company that designs and supports hotels and other hospitality brands appears on a ransomware group's leak site, the practical concern is straightforward: internal files may have left the organisation, and people whose details sit inside those systems could face identity misuse, targeted fraud, or unwanted contact. Public reporting does not yet say how many individuals are involved or exactly which records were taken, so anyone who has worked with, contracted for, or stayed in properties connected to the Gettys Group has reason to treat the claim seriously and check their own exposure.
On 28 February 2025 the domain gettys.com was listed by the ransomware group known as Qilin. The listing asserts that internal files were exfiltrated in a ransomware attack. No confirmed figure for affected people has been published, and the precise contents of the files remain undisclosed beyond that general description.
What happened
According to the available record, gettys.com was listed by the Qilin ransomware group on 28 February 2025. The group claims that internal files belonging to the organisation were exfiltrated during a ransomware attack. The number of people affected is unknown. No public timeline of the intrusion, no technical description of the initial access method, and no statement confirming or denying the claim from the company itself appear in the facts provided. The incident is therefore known only through the leak-site listing and the accompanying assertion that internal files were taken.
Who is qilin?
Qilin is a ransomware operation that has been active for several years and is widely documented as a ransomware-as-a-service (RaaS) group. It typically encrypts victim systems and simultaneously steals data, then threatens to publish the stolen material on a dedicated leak site if a ransom is not paid. The group has previously listed organisations across multiple sectors, including professional services, manufacturing and hospitality-related firms. Its public posts usually name the victim, sometimes display sample files, and set a countdown before full publication. In this case the listing of gettys.com is a claim made by the group; it has not been independently confirmed in the supplied facts, and no specific statements by Qilin about the content or volume of data from this particular victim are recorded beyond the general assertion of internal-file exfiltration.
gettys.com and its sector
The Gettys Group is described as a family of hospitality-focused companies that work with developers, operators and brands to create guest experiences and brand details. For more than three decades it has operated in the hospitality design and consulting space. Organisations of this type routinely hold project files, contracts, employee records, vendor information, client contact lists and sometimes guest-related data gathered during brand or property work. A breach at such a firm is consequential because the data often spans multiple properties, partners and individuals who never deal directly with the design company itself, yet whose personal or commercial details may reside in shared systems.
What data was at risk
The facts state that internal files were exfiltrated in a ransomware attack. No further breakdown—such as whether those files contained names, addresses, financial details, passport numbers, employee records or proprietary design documents—has been disclosed. People affected remain unknown. Hospitality-sector firms of this kind typically store contracts, personnel data, client correspondence and project materials; any of those categories could be present. Because the exact contents are unconfirmed, it is not possible to state with certainty which specific data types left the organisation.
Why it matters
For individuals, the real-world risk is that personal or professional information, if present in the stolen files, could be used for phishing, social-engineering calls, credential stuffing or identity fraud. Even limited internal documents can reveal enough context for convincing scams. For the organisation, the consequences include potential regulatory notification duties, contractual obligations to clients and partners, reputational damage, and the operational cost of investigating and remediating the incident. Because the scale is unknown, both the company and any third parties whose data may have been held must treat the claim as a live risk until more detail emerges or is ruled out.
Were you affected?
If you have been an employee, contractor, client or guest connected to Gettys Group projects, monitor financial accounts and watch for unexpected emails or calls that reference hospitality work. Change passwords on any accounts that reused credentials linked to the company, and enable multi-factor authentication where available. Consider placing a fraud alert with credit bureaus if you believe sensitive personal data may have been involved. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets; doing so provides an early signal even when the full contents of this particular incident remain unconfirmed.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Maine Course Hospitality Group Listed by qilin Ransomware GroupMango's Tropical Cafe Listed by qilin Ransomware GroupLaloma Listed by qilin Ransomware GroupIndian Spring Country Club Listed by qilin Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the gettys.com Listed by qilin Ransomware Group →
Publicly posted by qilin — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.