Monday, April 28, 2025
HomeComputer SecurityHackers Selling More than 200 Million Stolen Data from Chinese Hotel Chain...

Hackers Selling More than 200 Million Stolen Data from Chinese Hotel Chain in Dark Web

Published on

SIEM as a Service

Follow Us on Google News

Hackers advertising and selling more than 200 million highly sensitive data in a Dark web forum that was stolen from the China-based hotel chain.

Initially, researchers believe that the stolen information is only personally identifiable information (PII) of Chinese customer but further analysis helps then to uncovered that the stolen information from other Asian countries as well.

These stolen data belong to one the data breach that reported in last August 29 that exposed up to 130 million PII from Huazhu Hotels Group.

- Advertisement - Google News

A Dark web forum that advertises these stolen data for the cost of eight bitcoins that is roughly around  US$58,000.

Advertising Data Amount from Hacked Database Data

Hackers claiming that the First set of stolen data contains various sensitive information including names, mobile phone numbers, email addresses, ID numbers, and residential addresses, among others from 53GB data contain 123 million records.

The second set of data contain 130 million customer ID information such as registered check-in time, customer name, ID number, home address, birthday, and internal ID number from 22.3 GB data.

Third dark web advertisement refers around 240 million records from 66.2GB data which including customer names, room numbers, card numbers, mobile numbers, email addresses, check-in and departure times, and hotel ID numbers.

Apart from this, Buyers and members of the dark web forum specifically request the particular set of data, for example, one of the forum members asked only a female data.

Selling Stolen Data and Compromised Victims are not limited

According to Trend Micro research, The data from the hotel chain is only a portion of what’s being sold in the deep web forum. The following is an example of other stolen data and illicit products we found being sold in the forum:

  1. Student-, hotel-, and financial investment-related PII. This PII included full names, Alipay accounts, WeChat bills, debit card, and other finance-related data.
  2. Banking and ID card information; interestingly, this is sold in the form of pictures of people holding the IDs, likely done as proof of identification.
  3. PII of contestants of a national pageant. The PII included names, physical attributes, and social media accounts.
  4. Stolen Taiwanese and Brazilian credit card data (payment can be sent to the user’s Steam account).
  5. PII of residents in Beijing.
  6. China national passports and other documents.
  7. Personal pictures of young female users in QQ accounts.

Our various research efforts showed that stolen and leaked PII is a staple offering in many cybercriminal underground marketplaces, which makes data privacy and security a must for organizations, Trend Micro said.

Also Read:

Tor Browser for Android – Browse Anonymously on Android Devices

Mobile Spyware Maker mSpy Leaked Millions of Sensitive Data Online in Plain Text

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Critical FastCGI Library Flaw Exposes Embedded Devices to Code Execution

A severe vulnerability (CVE-2025-23016) in the FastCGI library-a core component of lightweight web server...

Viasat Modems Zero-Day Vulnerabilities Let Attackers Execute Remote Code

A severe zero-day vulnerability has been uncovered in multiple Viasat satellite modem models, including...

Obfuscation Techniques: A Key Weapon in the Ongoing War Between Hackers and Defenders

Obfuscation stands as a powerful weapon for attackers seeking to shield their malicious code...

React Router Vulnerabilities Allow Attackers to Spoof Content and Alter Values

The widely used React Router library, a critical navigation tool for React applications, has...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Cybercriminals Selling Sophisticated HiddenMiner Malware on Dark Web Forums

Cybercriminals have begun openly marketing a powerful new variant of the HiddenMiner malware on...

FortiGate 0-Day Exploit Allegedly Up for Sale on Dark Web

A chilling new development in the cybersecurity landscape has emerged, as a threat actor...

Over 26,000 Dark Web Discussions Focused on Hacking Financial Organizations

Radware’s comprehensive research into the cybersecurity landscape has uncovered significant trends shaping the financial...