Anubis group claimed 64 GB of Disneyland Paris files from a contractor

Organization
Disneyland Paris
Exploit
Third-Party Data Breach
Industry
Entertainment

On June 20, 2025 the Anubis ransomware-as-a-service operation added Disneyland Paris to its dark web leak site, claiming to hold a 64 GB archive of files relating to construction and renovation work at the resort. The group said the material had not come from Disney directly but from a breach at a partner company working on behalf of the park's operator.

Anubis put the haul at more than 39,000 files, including engineering documents, architectural and technical drawings, infrastructure plans and material covered by non-disclosure agreements, alongside several thousand photographs and videos. Samples posted to the site referenced attractions including Crush's Coaster, Phantom Manor, Ratatouille, Big Thunder Mountain, Buzz Lightyear, Autopia, Orbitron and Frozen-themed development. Cyber Daily reported that the group described the trove as the largest leak in the park's history and suggested competitors might find the documents valuable.

The listing carried a countdown indicating the files would be published within days. Anubis did not say whether it had issued a ransom demand, and did not claim to hold guest, employee or payment data. Anubis surfaced in December 2024, developing from an earlier test build known as Sphinx.

Neither Disneyland Paris nor The Walt Disney Company acknowledged the claim publicly, and outlets that approached the resort's press office received no response. The contractor said to be the source was never named. As of late June 2025 the incident remained unverified, resting on the attackers' own assertions and the samples they published.

Sources