REH Listed by blackbasta Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The REH Listed by blackbasta Ransomware Group (reported October 11, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Ransomware groups continue to target hospitality and private hotel operators, using double-extortion tactics that pair system encryption with the threat of publishing stolen files. In this landscape, even listings that supply limited public detail can signal real operational and personal risk for staff, guests and partners.
On 11 October 2023 the ransomware group blackbasta listed REH on its leak site, claiming to have exfiltrated internal files in a ransomware attack. The number of people affected remains unknown, and wider technical particulars have not been disclosed. The claim alone is enough to warrant careful attention from anyone connected to the organisation.
What happened
Public reporting states that REH was listed by the blackbasta ransomware group on 11 October 2023. According to the available record, the group asserts that internal files were exfiltrated during a ransomware attack. No confirmed figure for individuals affected has been released, and details such as the precise intrusion method, the duration of unauthorised access, or any ransom demand remain undisclosed. The listing itself constitutes the group’s claim; independent confirmation of the full scope has not been provided in the public facts.
Inside blackbasta
Blackbasta is a ransomware operation that emerged in 2022 and has since been documented in numerous incidents across Europe and North America. The group typically operates a double-extortion model: after gaining access, often through compromised credentials, phishing or exploited vulnerabilities, operators exfiltrate data before encrypting systems and threatening to publish the stolen material if payment is not made. Blackbasta has been observed using leak sites to name victims and, in some cases, to release sample files as proof. Its affiliates have targeted a range of sectors, including manufacturing, professional services and hospitality. Claims posted on such sites are assertions by the actors and are not automatically verified; organisations and investigators treat them as leads requiring corroboration.
REH and its sector
REH is identified in the public summary with Edwardian Hotels London, described as one of the United Kingdom’s largest privately owned hotel groups. The group owns and operates a portfolio of four- and five-star hotels and restaurants, including properties such as The Londoner, The May Fair, The Edwardian Manchester and multiple Radisson Blu Edwardian hotels across London. Hospitality businesses of this type routinely manage reservations, guest profiles, payment information, employee records and commercial contracts. A breach affecting such an operator is consequential because it can expose both customer and staff data, disrupt booking and operational systems, and damage trust in a sector that depends on reputation and repeat custom. The facts do not establish negligence or specific security failings; they simply record the listing and the claimed exfiltration of internal files.
The information in question
The only data type named in the available record is “internal files exfiltrated in ransomware attack.” No further breakdown—such as whether guest records, payment card data, employee details, contracts or operational documents were included—has been disclosed. Organisations in the hotel sector typically hold reservation histories, contact and identification details, loyalty-programme information, staff HR files and supplier agreements. Because the precise contents remain unconfirmed, it is not possible to state what was taken beyond the general description of internal files. Anyone who has stayed at, worked for or done business with the group should treat the possibility of exposure as open until clearer inventories are published.
The real-world impact
For individuals, the practical risks centre on misuse of any personal or financial information that may have been among the internal files. That can include targeted phishing, identity fraud or unsolicited contact that appears to come from the hotel group. For the organisation, consequences may include operational disruption, regulatory notification duties, contractual issues with partners and the longer-term cost of restoring systems and confidence. Because the number of people affected is unknown and the exact data types are not itemised, the scale of these risks cannot yet be quantified from public information alone. Calm monitoring and basic protective steps remain the proportionate response while further detail is awaited.
If your data was in this claimed breach
If you have a past or present connection to REH or Edwardian Hotels London—as a guest, employee or supplier—begin by watching bank and card statements for unfamiliar charges and by treating unexpected emails or calls that reference a stay or booking with caution. Enable multi-factor authentication on email and financial accounts, and consider placing fraud alerts with relevant credit-reference services if you believe sensitive identifiers may have been involved. Change passwords on any accounts that reused credentials linked to hotel logins or loyalty programmes. You can also run a free exposure scan of your email address to check whether it has already appeared in known breach datasets; that step provides an additional, concrete signal while official notifications, if any, are still pending.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
hotelplan.co.uk Listed by blackbasta Ransomware Groupedwardian.com Listed by blackbasta Ransomware GroupEdwardian Hotels London Listed by blackbasta Ransomware GroupParklane Group Listed by blackbasta Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the REH Listed by blackbasta Ransomware Group →
Publicly posted by blackbasta — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.