Description

The Daixin Team ransomware group recently targeted Omni Hotels & Resorts in a cyberattack, leading to a widespread IT outage affecting reservation systems, hotel room locks, and point-of-sale (POS) terminals. The hotel chain confirmed the attack, stating that they took immediate action to shut down systems and contain data. Despite their efforts, Daixin Team added Omni Hotels to their dark web leak site, threatening to release sensitive customer information unless a ransom is paid. Although Daixin Team has not yet provided proof on their leak site, they shared screenshots of stolen data with DataBreaches.net, revealing over 3.5 million records of Omni Hotels visitors with names, email addresses, and mailing addresses. This incident follows a pattern of the group targeting organizations, encrypting systems, stealing data (including patient health and personally identifiable information), and then pressuring victims for ransom payments under the threat of public data release. Daixin Team's modus operandi involves exploiting vulnerabilities in VPN servers or using compromised credentials with disabled multi-factor authentication (MFA) to gain access to networks. Omni Hotels, operating in the US, Canada, and Mexico with numerous properties, has faced previous security challenges, including a 2016 data breach where POS malware was used to steal payment card information from hotel guests.