CSIDB logo
Incident

Melia Hotels International

Incident posture

Attack window
Oct 2021
Location
Spain
Status
Historical
CIA posture
Available to members
Updated
2025-10-23 00:00

Linked entities

Victim
Melia Hotels International
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Oct 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack disrupted internal networks and web-based systems, including reservations and public websites, primarily affecting Spain-based operations of a major global hotel chain. The incident, reported as ransomware by local media but unclaimed by any group, led to system restoration from backups within days, with operations resuming normally while collaborating with cybersecurity experts and authorities.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On October 4, 2021, Meliá Hotels International experienced a cybersecurity incident that disrupted operations across its Spain-based infrastructure. The attack began in the early hours of Monday, targeting internal networks and web-based servers critical to business functions. Primary impacts included the compromise of the company’s reservation system and public-facing websites, which hindered booking capabilities and digital customer interactions. Multiple Spanish media outlets characterized the event as a ransomware attack, though no ransomware group publicly claimed responsibility or listed Meliá on leak sites during the immediate aftermath. The hotel chain, ranked among the world’s largest with over 370 properties in 40+ countries, prioritized containment by isolating affected systems. It promptly notified Spanish financial regulators and law enforcement agencies while engaging Telefonica’s cybersecurity division for forensic support and recovery assistance.

Meliá’s incident response team initiated restoration procedures using backup systems, enabling a return to normal operations within days. This rapid recovery minimized disruptions to guest services, with hotels continuing to accommodate visitors throughout the incident. The company did not publicly disclose technical details regarding the attack vector, data compromise, or financial impact. A spokesperson declined further commentary beyond confirming remediation efforts, and Spanish authorities maintained silence due to the ongoing investigation. No subsequent updates revealed whether threat actors exfiltrated data or demanded ransom. The incident underscored the operational resilience of Meliá’s backup infrastructure while highlighting persistent threats to critical hospitality sector systems like reservations and customer-facing platforms.

Sources

Sources available to members: 1 source.

CSIDB