The NightSpire ransomware operation claimed to have breached Hyatt, offering a free download of 48.5 GB of data allegedly stolen from the Hyatt Place Chelsea New York hotel. Reported sample files include invoices and expense reports containing employee names, contact details, signatures, and partner information; researchers suggested the material may have been taken from an internal CMS and warned that any associated credential compromise could enable broader internal access and lateral movement.
Separately, Indian music streaming service Raaga reportedly suffered a breach affecting ~10.2 million users, with the dataset advertised for sale on underground forums and flagged via Have I Been Pwned. Exposed data reportedly includes names, emails, demographic/location fields, and passwords stored as unsalted MD5 hashes, increasing the likelihood of password cracking and downstream credential stuffing. Other items in the set are not incident-specific and instead cover general industry sentiment and reporting on privacy/attack-surface priorities (polling and commentary), as well as healthcare/ambulance-service breach statistics and crypto-scam reporting that reference breaches in passing rather than detailing a single, shared event.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
The NightSpire ransomware operation allegedly claimed it breached the Hyatt Place Chelsea New York hotel and offered a free download of 48.5 GB of purportedly stolen data. Analysis of sample files indicated the leak included invoices and expense reports with employee names, contact details, signatures, and partner company information, possibly from the hotel's internal CMS.
After the Raaga compromise, the stolen database was reportedly advertised for sale on an underground hacking forum or cybercrime marketplace. Have I Been Pwned reportedly detected the breach after threat actors posted the alleged dataset.
Indian music streaming platform Raaga reportedly suffered a breach in December 2025 that exposed personal information tied to about 10.2 million users. The compromised data reportedly included roughly 10 million unique email addresses, names, demographic and location data, and passwords stored as unsalted MD5 hashes.
SOCRadar said the NightSpire ransomware group emerged in March 2025 and has mostly targeted organizations in the United States since then. This provides the campaign context for its later Hyatt claim.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.