Ransomware gang NightSpire claims Hyatt data breach

A ransomware group known as NightSpire has claimed responsibility for hacking into Hyatt's systems and stealing data. The group states it has obtained nearly 50GB of files from the hotel chain, which it plans to sell. This incident highlights ongoing cybersecurity threats to the hospitality sector.

The ransomware gang NightSpire announced on January 20, 2026, that it had infiltrated Hyatt's computer systems and extracted sensitive information. According to the group's statement, the breach resulted in the theft of almost 50GB of data, which NightSpire is now offering for sale on underground forums.

Hyatt, a major global hospitality company, has not yet issued an official response to the claim as of the publication date. Such ransomware attacks often involve demands for payment to prevent data leaks, though NightSpire's specific demands remain unclear from available details.

This event underscores the persistent vulnerability of large corporations to cyber threats, particularly in industries handling customer data. Previous incidents in the hospitality sector have led to significant disruptions and financial losses, prompting increased investments in cybersecurity measures.

Experts note that verifying such claims is crucial, as some groups exaggerate breaches for notoriety. However, the volume of data mentioned suggests a potentially serious compromise if confirmed.

Related Articles

Nintendo has confirmed that data was stolen during a cyberattack involving a third party. The company noted that no significant secrets were revealed in the breach. A group identifying itself as Shadowbyt3$ is demanding $2 million for the stolen data.

Reported by AI

As the April 14 ransom deadline approaches, ShinyHunters has reiterated threats to release breached Rockstar Games data obtained via third-party Anodot, following the studio's confirmation of limited non-material access with no player impact. This updates coverage of the initial breach claim reported earlier this week.

Executives at West Pharmaceutical Services revealed details of a recent cybersecurity breach during a fireside chat at the Bank of America Global Healthcare Conference. The company issued an 8-K filing the previous evening after detecting an intruder in its systems. Officials described shutting down global operations to assess the situation.

Reported by AI

Inditex, the textile group behind Zara, disclosed on Wednesday night an unauthorized access to internal databases hosted on a third-party provider's servers. The company states no customer personal data, such as names, phones or credit cards, was compromised. Operations remain fully unaffected.

This website uses cookies

We use cookies for analytics to improve our site. Read our privacy policy for more information.
Decline