A Safepay ransomware attack on Holiday Inn Vilnius has led to the publication of personal information belonging to more than 500 guests and over 100 employees. The stolen archive reportedly contains about 74,000 files totalling 26.6 GB.
The incident became public after the hotel appeared on Safepay’s leak site on 28 September 2026. The data was subsequently published late on 1 October or overnight into 2 October, reportedly after a ransom was not paid.
Safepay ransomware attack timeline
Holiday Inn Vilnius is a 134-room hotel operated by Valmeda under the IHG Hotels and Resorts brand. Lithuanian cybersecurity company EcomWall identified the compromised information while monitoring ransomware publication sites and analysed the contents of the leaked archive.
24 September: Data reportedly copied
EcomWall’s analysis indicates that the attackers copied the data on 24 September 2026. The scale and range of the files suggest that the intrusion reached broadly across Valmeda’s business systems rather than being confined to a small set of isolated documents.
No public forensic report has established how the attackers first entered the environment, how long they had access or whether systems were encrypted. There is also no confirmed connection to a particular software vulnerability, compromised account or exposed device.
28 September: Hotel added to leak site
On 28 September, Safepay listed Holiday Inn Vilnius on its ransomware leak site. Several cyber threat intelligence monitors recorded the listing on that date, providing the earliest public evidence of the incident.
Ransomware groups use such listings to pressure victims during extortion negotiations. A listing may initially identify an organisation and threaten disclosure, with download links or the complete dataset added later if the attacker claims its demands have not been met.
1 to 2 October: Stolen files published
The Safepay ransomware data appears to have been released late on 1 October or during the overnight period into 2 October. The hotel later said the information had been published on the previous Thursday, which points to 1 October. Reports issued on 2 October described publication as happening during the night, creating a small but understandable difference in the recorded timing.
Lithuanian media began reporting the incident publicly on 2 October, citing EcomWall’s findings. By that stage, the case had progressed beyond an unverified criminal claim because researchers had examined the archive and identified customer and employee records.
5 October: Police confirm investigation
On 5 October 2026, Vilnius County Police confirmed that a pretrial investigation had been opened under prosecutorial oversight. The hotel said it had informed the police, Lithuania’s National Cyber Security Centre and the State Data Protection Inspectorate.
Holiday Inn Vilnius also said affected people would be notified once the relevant information had been confirmed. The investigation remains active, and no public statement has identified the initial access route or disclosed whether the attackers disrupted hotel operations.
Data exposed in the Safepay ransomware leak
The published archive reportedly includes customer booking information, identity details, payroll records, tax declarations and copies of official documents. This combination creates different risks for guests and staff, including targeted fraud and convincing impersonation attempts.
More than 500 hotel customers affected
The guest information is understood to relate to stays between 28 July and 3 August 2026 on one floor of the hotel. EcomWall estimated that the Safepay ransomware leak affects more than 500 customers representing over 45 countries.
Reportedly exposed fields include:
- Guest names and surnames
- Nationalities and home addresses
- Identity document numbers
- Hotel arrival and departure dates
Stay dates can make the breach particularly intrusive. Combined with names, addresses and identity numbers, they can help criminals create credible messages that refer to a real journey, hotel booking or payment.
Payroll and identity records for employees
The employee material reportedly includes payroll and tax declarations involving more than 100 staff. National personal codes, income details, tax information, passports and residence permits were also identified within the Safepay ransomware archive.
Social insurance documentation relating to 56 individuals was reportedly present. These files may contain multiple identifiers in a single document, increasing the potential value of the information for identity fraud or employee-focused social engineering.
Systems and versions remain undisclosed
No affected product, platform or software version has been publicly identified. It is therefore not possible to associate the attack with a CVE, apply a vulnerability-specific patch or conclude that systems used by other Holiday Inn properties are exposed in the same way.
The confirmed victim is Holiday Inn Vilnius and its operator, Valmeda. The available evidence does not establish that IHG’s wider international environment was compromised.
How Safepay ransomware operations work
Safepay is associated with double extortion, in which attackers steal information and then threaten to publish it if the victim does not pay. In this incident, the leak-site listing followed by publication is consistent with that model.
Across other Safepay ransomware cases, reported entry methods have included misuse of valid accounts and exploitation of public-facing applications or edge devices. However, these are general observations and have not been confirmed as the route into Holiday Inn Vilnius.
Researchers have also associated Safepay operations elsewhere with a LockBit 3.0-derived encryptor, files carrying the .safepay extension and ransom notes named readme_safepay.txt. None of these technical artefacts has been publicly confirmed in this hotel incident. No victim-specific indicators of compromise have been released by the hotel, police or EcomWall.
Current Safepay ransomware exploitation status
This is a confirmed in-the-wild criminal operation rather than a proof-of-concept vulnerability. Safepay claimed the victim, and researchers subsequently found the stolen records available online.
Publication means the risk no longer depends on whether Safepay retains the files. Once an archive is accessible, other criminals can copy, redistribute and search it even if the original leak is later removed. The police investigation and regulatory notifications are continuing as of 5 October 2026.
Why the Holiday Inn Vilnius leak matters
The incident demonstrates how a single compromise can expose both customer records and sensitive workforce documentation. Hospitality businesses commonly retain booking histories and identity details while also managing payroll, tax and immigration records for staff.
The international scope is also significant. With customers from more than 45 countries reportedly involved, notification and fraud monitoring may extend well beyond Lithuania.
What organisations should do now
Hotels and organisations connected to hospitality networks should use this Safepay ransomware incident as a prompt for targeted checks, particularly where identity documents and employee records are stored together.
- Review remote access, public-facing services and edge devices for unexplained access around 24 September 2026.
- Check privileged and service accounts for stolen credentials, unusual logins and large data transfers.
- Identify where passport copies, guest addresses and payroll records are stored, then restrict access and retention.
- Prepare specific warnings for affected people about messages referring to genuine stays, employment details or identity documents.
- Monitor criminal leak sites and threat intelligence feeds, as a victim listing can precede full publication.
Because no specific vulnerability or product has been identified, organisations should avoid assuming that one patch resolves the threat. The immediate priority is detecting unauthorised access, limiting exposure of high-value personal data and preserving evidence for investigation.
Originally reported by lrt.lt.






