Hoteles Globales Listed by malas Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Hoteles Globales Listed by malas Ransomware Group (reported April 9, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
For guests, staff and partners connected to Hoteles Globales, the appearance of the company on a ransomware leak site raises immediate practical questions: whether personal or booking-related information left the organisation’s systems, and what that could mean for identity misuse, targeted fraud or unwanted contact. Public reporting places the listing on 9 April 2023 and attributes it to the group known as malas; the number of people affected remains unknown, and the precise contents of any taken data have not been fully detailed beyond a description of internal files.
What is known is limited but concrete enough to warrant attention. The incident is described as a ransomware attack in which internal files were allegedly exfiltrated, with the intrusion linked to exploitation of a Zimbra vulnerability. Until the organisation or independent investigators publish fuller confirmation, anyone who has stayed at, worked for or done business with Hoteles Globales has reason to treat the claim seriously and to take basic protective steps.
Breaking down the breach
According to the available record, Hoteles Globales was listed by the malas ransomware group on 9 April 2023. The reported summary states that the attackers used a Zimbra vulnerability and that internal files were exfiltrated in the course of a ransomware attack. No confirmed figure has been given for the number of people affected, and public detail does not specify the exact volume of data, the duration of unauthorised access, or whether encryption of systems accompanied the theft.
Zimbra is a widely used collaboration and email platform. Vulnerabilities in such software have historically been leveraged by ransomware operators to gain initial access, move laterally and stage data for removal before or during encryption. In this case the public facts stop at the claim of exploitation and exfiltration; they do not describe the specific vulnerability version, the timeline of detection, or any ransom demand. The listing itself remains an assertion by the group rather than an independently verified disclosure from the victim.
The group behind it: malas
Malas operates as a ransomware group that publishes victim names on leak sites to pressure organisations into paying. Like other actors in this category, it typically claims to have stolen data and threatens to release it if negotiations fail. Public reporting on malas has associated the group with double-extortion tactics—combining system disruption with the threat of data exposure—though the precise tooling, affiliates and internal structure of the group are not fully transparent.
In the Hoteles Globales case, the group’s leak-site listing constitutes its claim that it obtained internal files. No further statements from malas about this specific victim—such as sample files, exact data categories or a confirmed release—are included in the facts at hand. Readers should therefore treat the attribution and the scope of the theft as claims pending corroboration, while recognising that ransomware groups have repeatedly demonstrated the ability to exfiltrate material once they hold valid access credentials or exploit unpatched services.
Who is Hoteles Globales?
Hoteles Globales is a hospitality organisation. Companies in this sector manage hotel properties, reservations, guest services and related corporate functions. They routinely handle booking records, contact details, payment information, loyalty or membership data, employee records and internal operational documents. Even when a breach is described only as involving “internal files,” the nature of hotel operations means those files can intersect with both customer and staff information.
A ransomware incident at a hotel group is consequential because the business depends on continuous availability of reservation and property-management systems and because guests reasonably expect their stay-related data to remain confidential. Disruption can affect check-ins, payments and communications; data exposure can create longer-term risks for individuals whose details appear in guest histories, invoices or correspondence. Public facts do not state the geographic footprint or size of Hoteles Globales’s operations, so the potential reach of any compromised records cannot be quantified from the listing alone.
The information in question
The facts name the exposed material as internal files exfiltrated in a ransomware attack. No further breakdown—such as whether the files included guest databases, employee records, financial documents, email archives or configuration data—is provided. The number of people affected is listed as unknown.
Organisations of this type typically hold names, addresses, phone numbers, email addresses, reservation histories, payment-card or billing data (sometimes tokenised), passport or identification details for certain stays, and staff HR information. It is possible that some or none of those categories were present in the taken files; the public record simply does not confirm the exact contents. Until Hoteles Globales or a competent authority publishes a clearer inventory, any assertion about specific data elements remains unconfirmed.
Why it matters
For individuals, the practical risks centre on misuse of personal information. If contact details or booking histories were among the internal files, affected people may face phishing emails or calls that reference real stays, increasing the chance that fraudulent messages appear legitimate. Payment or identity data, if present, could support account takeover or financial fraud. Even purely internal documents can contain enough contextual information to enable social-engineering attacks against staff or partners.
For the organisation, a ransomware event that includes exfiltration creates operational, legal and reputational exposure. Systems may have been encrypted or taken offline; regulatory obligations around personal-data breaches may apply depending on jurisdiction and the nature of the records; and trust among guests and corporate clients can erode if communication is delayed or incomplete. Because the scale and exact data types remain undisclosed, the full extent of these consequences cannot yet be measured from public sources alone.
The reported use of a Zimbra vulnerability also underscores a broader pattern: collaboration platforms are high-value targets. When such software is reachable from the internet and unpatched, it offers attackers a direct path into email and file stores that often contain precisely the internal material ransomware groups later advertise.
Were you affected?
If you have been a guest, employee or business partner of Hoteles Globales, treat the April 2023 listing as a prompt to act cautiously rather than as proof that your own data was taken. Monitor bank and card statements for unfamiliar charges, be sceptical of unsolicited messages that reference hotel stays or ask for credentials or payment, and consider changing passwords on accounts that reused credentials associated with hotel bookings or corporate email. If you receive notification directly from the company, follow its guidance and use only official contact channels.
You can also run a free exposure scan of your email address to check whether it has already appeared in known breach datasets. That step will not confirm or rule out involvement in this specific incident, but it can surface other exposures that warrant the same protective measures—unique passwords, multi-factor authentication where available, and ongoing vigilance against social engineering.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Cosmos Hotel Group Listed by malas Ransomware GroupBoarding Concept Listed by malas Ransomware GroupГород Кафе Listed by malas Ransomware GroupHotel Smeraldo Listed by malas Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Hoteles Globales Listed by malas Ransomware Group →
Publicly posted by malas — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.