ODALYS Listed by cactus Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The ODALYS Listed by cactus Ransomware Group (reported October 10, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
On 10 October 2023, the French holiday-accommodation company ODALYS was listed by the ransomware group known as cactus. Public reporting states that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and further operational details have not been disclosed.
The listing itself is a claim published by the group. For customers, partners and staff who deal with ODALYS, the incident raises ordinary questions about what may have left the organisation’s systems and what practical steps are worth taking while fuller information is still limited.
Breaking down the breach
According to the available record, ODALYS appeared on a cactus leak-site listing dated 10 October 2023. The only data description given is that internal files were allegedly exfiltrated in a ransomware attack. No confirmed figure for the volume of data, no list of specific file categories beyond that general description, no statement of whether systems were encrypted, and no public timeline of intrusion or discovery have been supplied in the facts at hand. The number of individuals potentially affected is recorded as unknown. In short, the public picture is limited to the group’s claim that it held and removed internal material from the company.
Who is cactus?
Cactus is a ransomware operation that has been observed in public reporting since 2023. Like many contemporary groups, it is associated with double-extortion tactics: operators seek to copy data before or during encryption and then threaten to publish or sell the material if a ransom is not paid. Victims are commonly named on dedicated leak sites, which serve both as pressure and as a public claim of success. The group has been linked to attacks across multiple sectors; its tooling and negotiation style are documented in industry write-ups, but those general patterns do not by themselves prove any specific technical detail about the ODALYS incident beyond what the listing asserts. Any statement that cactus “stole” particular ODALYS files should therefore be read as the group’s unverified claim unless independently confirmed.
Who is ODALYS?
ODALYS, operating principally as Odalys Vacances, is a significant player in the European holiday-rental market. Public descriptions state that it welcomes more than two million tourists a year across mobile-home campsites, ski chalets, holiday residences, clubs, apartments and city-centre hotels, with properties by the beach, in the mountains and in the countryside. Its website is www.odalys-vacances.com; reported revenue is approximately $151.1 million, and its address is given as 2 Rue De La Roquette, Passage Du Cheval Blanc, Cour De Mai, Paris, France. Organisations of this type routinely manage customer booking records, payment-related data, identity details for guests and staff, supplier contracts, and internal operational documents. A breach affecting such a company is consequential because the same systems that enable large-scale tourism bookings also concentrate personal and commercial information that can be misused if it leaves controlled environments.
What was likely exposed
The facts name only “internal files exfiltrated in ransomware attack.” No inventory of those files, no confirmation of customer databases, payment card data, employee records or other categories, and no headcount of affected individuals have been published in the material provided. Exact contents therefore remain unconfirmed. Companies in the holiday-accommodation sector typically hold reservation histories, contact details, travel dates, sometimes passport or identity copies for check-in, staff HR files, and commercial agreements with property owners and partners. Whether any of those categories were among the material cactus claims to have taken is not established by the public record. Readers should treat speculation about precise data types as unverified until ODALYS or independent investigators provide clearer disclosure.
What's at stake
For individuals, the main practical risks are misuse of personal contact or booking information—phishing that impersonates the company, attempts to reset accounts with known email addresses, or social-engineering calls that reference a real stay. If identity or payment-related data were involved (still unconfirmed), the usual secondary risks of fraud or account takeover would apply. For the organisation, exposure of internal files can mean operational disruption, regulatory notification duties under European data-protection rules, contractual issues with partners, and reputational cost while the scope stays unclear. None of these outcomes is automatic; they depend on what was actually copied and how it is later used. Because the scale and contents are undisclosed, the prudent stance is cautious monitoring rather than assumption of worst-case harm.
Were you affected?
If you have booked with ODALYS, worked for the company, or exchanged contracts with it, consider the following straightforward steps while official detail remains limited:
- Treat unsolicited messages that claim to be from ODALYS or about a “data incident” with caution; verify through official channels you already trust rather than links in the message.
- Change passwords on any account that reused a credential also used for ODALYS-related logins, and enable multi-factor authentication where available.
- Monitor bank and card statements for unfamiliar charges if you ever paid the company directly.
- Watch for phishing that references a real past reservation; do not supply new personal data in reply.
- Check whether your email address has appeared in known breach collections by running a free exposure scan, which can indicate whether that address has surfaced in previously published datasets (it will not prove or disprove involvement in this specific incident).
Public information on this event is still thin. Further clarity, if it comes, will most usefully come from the company itself or from regulators. Until then, ordinary hygiene—unique passwords, scepticism toward unexpected contact, and attention to financial alerts—remains the most reliable response.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Odalys Vacances Listed by cactus Ransomware GroupPromotrans Listed by cactus Ransomware GroupLagarde Meregnani Listed by cactus Ransomware Groupmillimages.com Listed by cactus Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the ODALYS Listed by cactus Ransomware Group →
Publicly posted by cactus — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.