ransomware
Credible
South Africa (ZA)
travel
BE Travel listed by the Arcus Media ransomware group
BE Travel
CompanyBE Travel
Domainbetravel.co.za
CountrySouth Africa (ZA)
Sectortravel
Breach date2026-07-13
People affectedNot disclosed
Ransomware grouparcusmedia
Data typesclient data, booking records, financial documents
Overview
The Arcus Media ransomware group has listed BE Travel, a South African executive travel agency trading as Baithaupi Executive Travel, on its leak site. The agency has operated for 19 years. The listing is dated 13 July 2026 with a deadline of 21 July 2026.

What was published
The group claims to have accessed the agency's systems and copied corporate data. Travel agencies hold client profiles, booking itineraries, payment details and supplier records, which are the expected contents of the leak.
Risks for affected individuals
- Corporate clients' travel and payment data may be exposed.
- Booking details could enable targeted fraud.
- Employee records may be included.
What remains unknown
- The volume of data exfiltrated.
- Whether the data has been published.
- The negotiation status.
What affected people should do
Corporate clients should verify any unusual payment requests and monitor card activity. The agency should notify clients and staff, secure its systems, and communicate the scope of the incident.
Sources
- http://arcuufpr5xxbbkin4mlidt7itmr6znlppk63jbtkeguuhszmc5g7qdyd.onion/?p=751