Pangea Listed by qilin Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Pangea was listed by the qilin ransomware group on October 15, 2025, after internal files were exfiltrated in a ransomware attack. An undisclosed number of people may have been affected; check whether your data appears in any breach disclosures and take appropriate steps.
When a travel agency appears on a ransomware group's leak site, the people who may feel the impact first are ordinary customers and staff whose personal details, booking histories or payment information could have been among the files taken. Public reporting so far gives no confirmed count of individuals affected and does not list every category of data, yet the mere claim that internal files were exfiltrated is enough to raise practical questions about identity theft, financial fraud and unwanted contact.
On 15 October 2025 the organisation known as Pangea was listed by the qilin ransomware group. The listing asserts that internal files were stolen in a ransomware attack; beyond that claim, independent confirmation of scale, exact timing or method remains limited. For anyone who has booked a trip, shared passport details or worked with the company, the episode underscores why even a boutique travel business can become a vector for real-world harm.
Inside the incident
Public detail on the incident itself is sparse. Reporting dated 15 October 2025 states that Pangea was listed by the qilin ransomware group and that the group claims internal files were exfiltrated during a ransomware attack. No figure for the number of people affected has been released, no inventory of the specific file types has been published by independent sources, and no timeline of initial access, encryption or negotiation has been disclosed. The available summary identifies the victim as PANGEA The Travel Store, a boutique travel agency, but does not elaborate on how the intrusion occurred or whether systems were restored. In short, the core facts rest on the group's own listing; everything else remains unconfirmed.
Inside qilin
Qilin is a well-documented ransomware operation that has operated for several years under a ransomware-as-a-service model. Public reporting consistently describes the group as using double-extortion tactics: encrypting systems while simultaneously stealing data and threatening to publish it on a dedicated leak site if payment is not made. Affiliates typically gain initial access through phishing, compromised credentials or unpatched remote services, then move laterally, exfiltrate files and deploy the ransomware payload. The group has previously claimed responsibility for attacks across multiple sectors and geographies, often posting sample files or directories to pressure victims. In this case the listing of Pangea is presented as a claim by the group; no independent verification of the stolen data volume or contents has been made public.
About Pangea
Pangea, trading as PANGEA The Travel Store, is described in available material as a boutique travel agency that designs bespoke, full-service trips tailored to individual tastes. It operates both an online platform and physical flagship stores, allowing customers to combine digital planning with face-to-face consultations. Organisations of this type routinely handle customer names, contact details, passport and visa information, travel itineraries, payment card data and correspondence with hotels, airlines and local operators. Staff records, supplier contracts and internal financial documents are also typical holdings. Because travel data often includes sensitive identity documents and future travel plans, a breach at such a firm can affect both private individuals and the company's commercial relationships.
What data was at risk
The only data category named in public reporting is "internal files exfiltrated in ransomware attack." No further breakdown—such as customer databases, employee records, financial statements or specific document types—has been confirmed. Travel agencies commonly store passport scans, frequent-flyer numbers, credit-card details, medical or dietary notes supplied for itineraries, and staff personal information. Whether any of those categories were among the files claimed by qilin is unconfirmed. Readers should therefore treat the precise contents as unknown until independent verification appears.
What's at stake
For individuals, the practical risks include identity fraud if passport or national-ID data were taken, financial loss if payment details may have been exposed, and targeted phishing that leverages knowledge of recent or upcoming trips. Staff may face similar exposure of payroll or personal contact information. For the organisation the stakes include operational disruption, potential regulatory scrutiny under data-protection rules, loss of customer trust, and the cost of forensic investigation and system recovery. Because the number of people affected remains unknown and the exact files are undisclosed, the full scope of these risks cannot yet be quantified; the prudent assumption is that anyone who has shared personal or payment information with the agency should monitor for misuse.
If your data was in this claimed breach
Begin by treating any unexpected communication that references your travel plans or personal details with caution; verify requests through official channels rather than links or numbers supplied in the message. Change passwords for accounts that reuse credentials you may have given the agency, enable multi-factor authentication where available, and review bank and credit-card statements for unfamiliar charges. Consider placing a fraud alert with credit bureaus if identity documents could have been involved. Finally, you can run a free exposure scan of your email address to check whether that address has already appeared in known breach data sets; doing so provides an early indication of whether further monitoring is warranted.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Noi Hotels Listed by qilin Ransomware GroupClub Atlético River Plate Listed by qilin Ransomware GroupBest Hotels Spain Listed by qilin Ransomware GroupWatermark Beach Resort Listed by qilin Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Pangea Listed by qilin Ransomware Group →
Publicly posted by qilin — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.