sbh Listed by qilin Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
sbh was listed by the qilin ransomware group on June 24, 2025, after internal files were exfiltrated in a ransomware attack. The number of people affected has not been disclosed; anyone with a relationship to sbh should check for official notices and change passwords or enable multi-factor authentication where possible.
People who have stayed at, worked for, or done business with BH Hotels & Resorts may now face uncertainty about whether their personal or commercial information sits among files claimed to have been taken in a ransomware attack. Public detail is limited, yet the listing of the organisation known as sbh by the qilin group on 24 June 2025 raises concrete questions about privacy, identity risk and operational disruption for guests and staff alike.
What is known so far is that the group asserts it has exfiltrated internal files. The number of people affected remains unknown, and independent confirmation of the claim has not been published. For ordinary travellers and employees, the practical stakes are straightforward: data that hotels routinely hold can be reused for fraud, phishing or further intrusion if it has truly left the organisation’s control.
Inside the incident
According to available reporting, sbh was listed by the qilin ransomware group on 24 June 2025. The group claims that internal files were exfiltrated in a ransomware attack. No public figure has been given for the volume of data, the number of systems involved, or the precise date the intrusion began. Method of initial access, ransom demand, and any negotiation outcome are undisclosed.
The organisation is identified in the listing material as BH Hotels & Resorts, operating properties in Fuerteventura, Lanzarote and Zanzibar. Beyond the assertion that internal files were taken, further technical specifics have not been released in the public record. The listing itself should be treated as an unverified claim by the threat actor until corroborated by the organisation or independent investigators.
Inside qilin
Qilin is a ransomware operation that has been publicly documented as following a double-extortion model: encrypting systems while also copying data and threatening to publish it on a dedicated leak site if payment is not made. The group has operated as a ransomware-as-a-service offering, allowing affiliates to deploy its tools in exchange for a share of proceeds. Its leak site has previously listed organisations across multiple sectors, using the threat of exposure to increase pressure.
Public reporting on qilin describes typical tactics that include phishing, exploitation of remote-access services, and lateral movement once inside a network. The group’s claims about any single victim, including sbh, remain assertions until verified. No statements attributed specifically to qilin about the contents or value of this particular set of files appear in the provided facts beyond the general claim of internal-file exfiltration.
Who is sbh?
sbh corresponds to BH Hotels & Resorts, a hospitality company that has operated for more than three decades. Its properties are described as modern hotels located on the first line in Fuerteventura, Lanzarote and Zanzibar, offering accommodation, dining, facilities and guest services. Organisations of this type sit at the intersection of tourism, local employment and international travel.
A breach involving a hotel group is consequential because such businesses routinely process guest reservations, payment details, staff records and supplier contracts. Guests may have shared passport or identity information for check-in; employees may have payroll and contact data on file; partners may have commercial agreements stored internally. Even when the exact scope of an incident is unconfirmed, the sector’s data holdings make any credible claim of exfiltration material to the people connected to those hotels.
The information in question
The facts state that the exposed material consists of internal files exfiltrated in a ransomware attack. No further breakdown of file types, databases or individual data elements has been disclosed. Public detail is therefore limited to that general description.
Hotels and resort operators typically hold guest contact details, booking histories, payment-card or billing information, loyalty-programme records, employee personal data, and internal operational documents. Whether any of those categories appear among the files claimed by qilin remains unconfirmed. Readers should not assume specific data types may have been exposed until the organisation or a verified investigation provides that information.
What's at stake
For individuals, the real-world risks centre on the possible misuse of personal or financial information if the claim proves accurate. Concrete concerns include:
- Targeted phishing or social-engineering attempts that reference a genuine stay or booking
- Identity-related fraud if identity documents or contact details were among internal files
- Unauthorised use of payment or loyalty information where such data was stored
- Secondary exposure of family members or colleagues whose details appear in shared records
For the organisation, stakes include operational disruption, regulatory scrutiny under data-protection rules, reputational damage among travellers, and the cost of investigation and remediation. Because the number of people affected is unknown and the precise contents unconfirmed, both individuals and the company face a period of uncertainty rather than a fully mapped incident.
What to do if you're exposed
If you have been a guest, employee or partner of BH Hotels & Resorts, treat the situation as a precautionary matter rather than confirmed personal compromise. Change passwords on any accounts that reused credentials associated with hotel bookings or staff portals. Monitor bank and card statements for unfamiliar charges. Be sceptical of unsolicited messages that claim to relate to a stay, refund or security update and that ask for personal details or urgent payment.
Enable multi-factor authentication wherever it is offered on email, banking and travel accounts. If you receive notification from the company itself, follow only the official channels it provides. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets; such a scan does not confirm involvement in this specific incident but can surface earlier exposures that warrant attention. Public detail on this event remains limited, so continued monitoring of official statements from the organisation is the most reliable next step.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Best Hotels Spain Listed by qilin Ransomware GroupGandía Palace Hotel Listed by qilin Ransomware GroupClub Lleuresport Listed by qilin Ransomware GroupPangea Travel Store Listed by qilin Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the sbh Listed by qilin Ransomware Group →
Publicly posted by qilin — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.