LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Pangea Listed by qilin Ransomware Group

HIGH severityUnverified claimHow we verify

Pangea Listed by qilin Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·October 15, 2025
Pangea Listed by qilin Ransomware Group

Reported October 15, 2025.

HIGH
Severity
October 15, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Pangea was listed by the qilin ransomware group on October 15, 2025, after internal files were exfiltrated in a ransomware attack. An undisclosed number of people may have been affected; check whether your data appears in any breach disclosures and take appropriate steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

When a travel agency appears on a ransomware group's leak site, the people who may feel the impact first are ordinary customers and staff whose personal details, booking histories or payment information could have been among the files taken. Public reporting so far gives no confirmed count of individuals affected and does not list every category of data, yet the mere claim that internal files were exfiltrated is enough to raise practical questions about identity theft, financial fraud and unwanted contact.

On 15 October 2025 the organisation known as Pangea was listed by the qilin ransomware group. The listing asserts that internal files were stolen in a ransomware attack; beyond that claim, independent confirmation of scale, exact timing or method remains limited. For anyone who has booked a trip, shared passport details or worked with the company, the episode underscores why even a boutique travel business can become a vector for real-world harm.

Inside the incident

Public detail on the incident itself is sparse. Reporting dated 15 October 2025 states that Pangea was listed by the qilin ransomware group and that the group claims internal files were exfiltrated during a ransomware attack. No figure for the number of people affected has been released, no inventory of the specific file types has been published by independent sources, and no timeline of initial access, encryption or negotiation has been disclosed. The available summary identifies the victim as PANGEA The Travel Store, a boutique travel agency, but does not elaborate on how the intrusion occurred or whether systems were restored. In short, the core facts rest on the group's own listing; everything else remains unconfirmed.

Inside qilin

Qilin is a well-documented ransomware operation that has operated for several years under a ransomware-as-a-service model. Public reporting consistently describes the group as using double-extortion tactics: encrypting systems while simultaneously stealing data and threatening to publish it on a dedicated leak site if payment is not made. Affiliates typically gain initial access through phishing, compromised credentials or unpatched remote services, then move laterally, exfiltrate files and deploy the ransomware payload. The group has previously claimed responsibility for attacks across multiple sectors and geographies, often posting sample files or directories to pressure victims. In this case the listing of Pangea is presented as a claim by the group; no independent verification of the stolen data volume or contents has been made public.

About Pangea

Pangea, trading as PANGEA The Travel Store, is described in available material as a boutique travel agency that designs bespoke, full-service trips tailored to individual tastes. It operates both an online platform and physical flagship stores, allowing customers to combine digital planning with face-to-face consultations. Organisations of this type routinely handle customer names, contact details, passport and visa information, travel itineraries, payment card data and correspondence with hotels, airlines and local operators. Staff records, supplier contracts and internal financial documents are also typical holdings. Because travel data often includes sensitive identity documents and future travel plans, a breach at such a firm can affect both private individuals and the company's commercial relationships.

What data was at risk

The only data category named in public reporting is "internal files exfiltrated in ransomware attack." No further breakdown—such as customer databases, employee records, financial statements or specific document types—has been confirmed. Travel agencies commonly store passport scans, frequent-flyer numbers, credit-card details, medical or dietary notes supplied for itineraries, and staff personal information. Whether any of those categories were among the files claimed by qilin is unconfirmed. Readers should therefore treat the precise contents as unknown until independent verification appears.

What's at stake

For individuals, the practical risks include identity fraud if passport or national-ID data were taken, financial loss if payment details may have been exposed, and targeted phishing that leverages knowledge of recent or upcoming trips. Staff may face similar exposure of payroll or personal contact information. For the organisation the stakes include operational disruption, potential regulatory scrutiny under data-protection rules, loss of customer trust, and the cost of forensic investigation and system recovery. Because the number of people affected remains unknown and the exact files are undisclosed, the full scope of these risks cannot yet be quantified; the prudent assumption is that anyone who has shared personal or payment information with the agency should monitor for misuse.

If your data was in this claimed breach

Begin by treating any unexpected communication that references your travel plans or personal details with caution; verify requests through official channels rather than links or numbers supplied in the message. Change passwords for accounts that reuse credentials you may have given the agency, enable multi-factor authentication where available, and review bank and credit-card statements for unfamiliar charges. Consider placing a fraud alert with credit bureaus if identity documents could have been involved. Finally, you can run a free exposure scan of your email address to check whether that address has already appeared in known breach data sets; doing so provides an early indication of whether further monitoring is warranted.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyPangea security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Pangea’s full breach history →

More recent breaches

Noi Hotels Listed by qilin Ransomware GroupMarch 26, 2026Club Atlético River Plate Listed by qilin Ransomware GroupDecember 19, 2025Best Hotels Spain Listed by qilin Ransomware GroupDecember 18, 2025Watermark Beach Resort Listed by qilin Ransomware GroupDecember 13, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Pangea Listed by qilin Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by qilin — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram