Motel One confirms data theft after ALPHV/BlackCat ransomware attack
- Organization
- Motel One
- Exploit
- Ransomware
- Industry
- Hospitality
The ALPHV/BlackCat ransomware group added the German budget hotel chain Motel One to its dark web leak site on September 30, 2023, claiming it had taken 24,449,137 files amounting to roughly six terabytes of data. The gang said the haul included three years of booking confirmations in PDF and RTF form, with customer names, addresses, reservation dates, payment methods and contact details, along with internal company documents and a quantity of credit card data. It gave the chain five days to respond before publishing.
Motel One, which operates around 90 hotels across Europe and the United States, acknowledged the attack in early October. The company said countermeasures had held the damage to what it described as a relative minimum, and that its business operations were never at risk.
The chain confirmed that attackers reached customer address data and the details of 150 credit cards, a figure far smaller than the volume the ransomware group advertised. TechCrunch reported that Motel One spokesperson Inken Mende did not respond to its questions, and that it was not known how the company was compromised or how it thwarted the attack.
TechCrunch reported that it had reviewed some of the purported employee and customer data the group had posted. As of early October 2023 the gap between the gang's claims and the company's own account of the breach remained unresolved, and Motel One had not published a count of affected guests.