ransomware
Credible
Egypt (EG)
hospitality
Rhactus Hotel listed by the LockBit ransomware group
Rhactus Hotel
CompanyRhactus Hotel
Domainrhactushotel.com
CountryEgypt (EG)
Sectorhospitality
Breach date2026-04-22
People affectedNot disclosed
Ransomware grouplockbit5
Data typesguest data, reservation records, internal documents
Overview
The LockBit ransomware group has listed Rhactus Hotel, an accommodation provider in El Alamein, Egypt, on its leak site. The listing appeared on 22 April 2026.

What was published
The group claims to have exfiltrated data from the hotel. Hospitality operations typically hold guest profiles, reservation records and internal administrative documents, which are the likely contents of any exfiltration.
Risks for affected individuals
- Guest personal data may be exposed.
- Reservation and payment records could enable fraud.
- Employees' records may be included.
What remains unknown
- Whether data has been exfiltrated.
- The volume of records involved.
- The timeline of any release.
What affected people should do
Recent guests should monitor payment activity and be cautious of unsolicited messages referencing the hotel. The property should notify guests and staff, review compromised systems, and communicate the scope of the incident.
Sources
- http://lockbitapt67g6rwzjbcxnww5efpg4qok6vpfeth7wx3okj52ks4wtad.onion/post/d31502c73b53b08c83038991b9ed763b