Menu
Browse

Cyber Incident Victim: Melia Hotels International

Date:

Oct 2021

Location:

Spain

Summary

A cyberattack disrupted internal networks and web-based systems, including reservations and public websites, primarily affecting Spain-based operations of a major global hotel chain. The incident, reported as ransomware by local media but unclaimed by any group, led to system restoration from backups within days, with operations resuming normally while collaborating with cybersecurity experts and authorities.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On October 4, 2021, Meliá Hotels International experienced a cybersecurity incident that disrupted operations across its Spain-based infrastructure. The attack began in the early hours of Monday, targeting internal networks and web-based servers critical to business functions. Primary impacts included the compromise of the company’s reservation system and public-facing websites, which hindered booking capabilities and digital customer interactions. Multiple Spanish media outlets characterized the event as a ransomware attack, though no ransomware group publicly claimed responsibility or listed Meliá on leak sites during the immediate aftermath. The hotel chain, ranked among the world’s largest with over 370 properties in 40+ countries, prioritized containment by isolating affected systems. It promptly notified Spanish financial regulators and law enforcement agencies while engaging Telefonica’s cybersecurity division for forensic support and recovery assistance.

Cyber Incident Image

Meliá’s incident response team initiated restoration procedures using backup systems, enabling a return to normal operations within days. This rapid recovery minimized disruptions to guest services, with hotels continuing to accommodate visitors throughout the incident. The company did not publicly disclose technical details regarding the attack vector, data compromise, or financial impact. A spokesperson declined further commentary beyond confirming remediation efforts, and Spanish authorities maintained silence due to the ongoing investigation. No subsequent updates revealed whether threat actors exfiltrated data or demanded ransom. The incident underscored the operational resilience of Meliá’s backup infrastructure while highlighting persistent threats to critical hospitality sector systems like reservations and customer-facing platforms.

Sources
Sources available to members
1 source