Opens in a new tab

Safepay Ransomware Leak Hits Holiday Inn Vilnius

Ransomware hits Holiday Inn Vilnius, customer and employee data published

A Safepay ransomware attack on Holiday Inn Vilnius has led to the publication of personal information belonging to more than 500 guests and over 100 employees. The stolen archive reportedly contains about 74,000 files totalling 26.6 GB.

The incident became public after the hotel appeared on Safepay’s leak site on 28 September 2026. The data was subsequently published late on 1 October or overnight into 2 October, reportedly after a ransom was not paid.

Safepay ransomware attack timeline

Holiday Inn Vilnius is a 134-room hotel operated by Valmeda under the IHG Hotels and Resorts brand. Lithuanian cybersecurity company EcomWall identified the compromised information while monitoring ransomware publication sites and analysed the contents of the leaked archive.

24 September: Data reportedly copied

EcomWall’s analysis indicates that the attackers copied the data on 24 September 2026. The scale and range of the files suggest that the intrusion reached broadly across Valmeda’s business systems rather than being confined to a small set of isolated documents.

No public forensic report has established how the attackers first entered the environment, how long they had access or whether systems were encrypted. There is also no confirmed connection to a particular software vulnerability, compromised account or exposed device.

28 September: Hotel added to leak site

On 28 September, Safepay listed Holiday Inn Vilnius on its ransomware leak site. Several cyber threat intelligence monitors recorded the listing on that date, providing the earliest public evidence of the incident.

Ransomware groups use such listings to pressure victims during extortion negotiations. A listing may initially identify an organisation and threaten disclosure, with download links or the complete dataset added later if the attacker claims its demands have not been met.

1 to 2 October: Stolen files published

The Safepay ransomware data appears to have been released late on 1 October or during the overnight period into 2 October. The hotel later said the information had been published on the previous Thursday, which points to 1 October. Reports issued on 2 October described publication as happening during the night, creating a small but understandable difference in the recorded timing.

Lithuanian media began reporting the incident publicly on 2 October, citing EcomWall’s findings. By that stage, the case had progressed beyond an unverified criminal claim because researchers had examined the archive and identified customer and employee records.

5 October: Police confirm investigation

On 5 October 2026, Vilnius County Police confirmed that a pretrial investigation had been opened under prosecutorial oversight. The hotel said it had informed the police, Lithuania’s National Cyber Security Centre and the State Data Protection Inspectorate.

Holiday Inn Vilnius also said affected people would be notified once the relevant information had been confirmed. The investigation remains active, and no public statement has identified the initial access route or disclosed whether the attackers disrupted hotel operations.

Data exposed in the Safepay ransomware leak

The published archive reportedly includes customer booking information, identity details, payroll records, tax declarations and copies of official documents. This combination creates different risks for guests and staff, including targeted fraud and convincing impersonation attempts.

More than 500 hotel customers affected

The guest information is understood to relate to stays between 28 July and 3 August 2026 on one floor of the hotel. EcomWall estimated that the Safepay ransomware leak affects more than 500 customers representing over 45 countries.

Reportedly exposed fields include:

  • Guest names and surnames
  • Nationalities and home addresses
  • Identity document numbers
  • Hotel arrival and departure dates

Stay dates can make the breach particularly intrusive. Combined with names, addresses and identity numbers, they can help criminals create credible messages that refer to a real journey, hotel booking or payment.

Payroll and identity records for employees

The employee material reportedly includes payroll and tax declarations involving more than 100 staff. National personal codes, income details, tax information, passports and residence permits were also identified within the Safepay ransomware archive.

Social insurance documentation relating to 56 individuals was reportedly present. These files may contain multiple identifiers in a single document, increasing the potential value of the information for identity fraud or employee-focused social engineering.

Systems and versions remain undisclosed

No affected product, platform or software version has been publicly identified. It is therefore not possible to associate the attack with a CVE, apply a vulnerability-specific patch or conclude that systems used by other Holiday Inn properties are exposed in the same way.

The confirmed victim is Holiday Inn Vilnius and its operator, Valmeda. The available evidence does not establish that IHG’s wider international environment was compromised.

How Safepay ransomware operations work

Safepay is associated with double extortion, in which attackers steal information and then threaten to publish it if the victim does not pay. In this incident, the leak-site listing followed by publication is consistent with that model.

Across other Safepay ransomware cases, reported entry methods have included misuse of valid accounts and exploitation of public-facing applications or edge devices. However, these are general observations and have not been confirmed as the route into Holiday Inn Vilnius.

Researchers have also associated Safepay operations elsewhere with a LockBit 3.0-derived encryptor, files carrying the .safepay extension and ransom notes named readme_safepay.txt. None of these technical artefacts has been publicly confirmed in this hotel incident. No victim-specific indicators of compromise have been released by the hotel, police or EcomWall.

Current Safepay ransomware exploitation status

This is a confirmed in-the-wild criminal operation rather than a proof-of-concept vulnerability. Safepay claimed the victim, and researchers subsequently found the stolen records available online.

Publication means the risk no longer depends on whether Safepay retains the files. Once an archive is accessible, other criminals can copy, redistribute and search it even if the original leak is later removed. The police investigation and regulatory notifications are continuing as of 5 October 2026.

Why the Holiday Inn Vilnius leak matters

The incident demonstrates how a single compromise can expose both customer records and sensitive workforce documentation. Hospitality businesses commonly retain booking histories and identity details while also managing payroll, tax and immigration records for staff.

The international scope is also significant. With customers from more than 45 countries reportedly involved, notification and fraud monitoring may extend well beyond Lithuania.

What organisations should do now

Hotels and organisations connected to hospitality networks should use this Safepay ransomware incident as a prompt for targeted checks, particularly where identity documents and employee records are stored together.

  • Review remote access, public-facing services and edge devices for unexplained access around 24 September 2026.
  • Check privileged and service accounts for stolen credentials, unusual logins and large data transfers.
  • Identify where passport copies, guest addresses and payroll records are stored, then restrict access and retention.
  • Prepare specific warnings for affected people about messages referring to genuine stays, employment details or identity documents.
  • Monitor criminal leak sites and threat intelligence feeds, as a victim listing can precede full publication.

Because no specific vulnerability or product has been identified, organisations should avoid assuming that one patch resolves the threat. The immediate priority is detecting unauthorised access, limiting exposure of high-value personal data and preserving evidence for investigation.

Originally reported by lrt.lt.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call