Ransom! TUI China (AUG-2026)
The TUI China ransomware claim attributed to the threat actor dragonforce, an affiliate of TUI Group, targets internal documentation including passports, visas, and legal and financial records, impacting the organization in China. The attack highlights the compromise of sensitive personal and corporate data associated with cross-border and legal travel processes in #China

Incident Details

  • Victim: TUI China
  • Sector: Hospitality
  • Country: CN
  • Actor: dragonforce
  • Source: http://z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid.onion/blog/?post_uuid=eac9b985-c649-480d-815d-805c0c980241
  • Discovered: 2026-08-03T06:52:53.230294+00:00
  • Published: 2026-08-03T06:45:27.037448+00:00

Information

  • An affiliate of TUI Group, the world’s number one leisure tourism business, established in late 2003 as the first joint venture with foreign majority share in the Chinese tourism industry.
  • Passports, visas, internal documentation, legal and financial documents, etc.

Disclaimer: This post is based on public claims made by the ransomware group "dragonforce". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live