Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo Hyatt Place New York / Chelsea Hotel

Group: Nightspire

Discovered by ransomware.live: 2026-01-14

Estimated attack date: 2025-12-14

Country: US

Data exfiltrated: 48.5 GB

Description:

Hyatt Place New York / Chelsea Hotel


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 26

Compromised Users: 18342

Third Party Employee Credentials: 450


External Attack Surface: 116


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse@gcd.com
MX Records
  • mxa-00114c02.gslb.pphosted.com.
  • mxb-00114c02.gslb.pphosted.com.
TXT Records
  • smartsheet-site-validation=jZXfaGsQ6iXHpqB6nFyAJpWcHF29Ez0V
  • sending_domain1101993=c08d9d95c8c968f8e820484228dfeb575ac3b6b2f3840b344ffd9028ba1f0b41
  • v=msv1" "t=A1108405-0ED8-484E-98F1-53648B951219
  • asv_domain=d540dc0bf45c573be8d5a70aba6de931
  • facebook-domain-verification=qq76mj47dy7kb3qfo082ldhy8c6r7b
  • v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com -all
  • docker-verification=0e314216-3c20-47e9-bddd-21ce94eab47c
  • apple-domain-verification=qpc48NtK6X1JIj47
  • k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCZfcs0PuISIjyNmkDXQkaZU3RXAru6BKdgyPQytVnD/vANEDKsaHyeIcX9Qy2/BJJ0QgrZ3V0UgAob+DuR4vElFkgn8R2p3CYYSXfpbtO2JVM3yUhAhb9TZarPvXa/+I8siMrV1tlBGsvnddWT+fZiNv736DtdWL1FcOP1D/U+uwIDAQAB
  • openai-domain-verification=dv-VVfWN61TYw54hcW26wna78sW
  • amazonses:FP7e8Mgqbhfb177AOPlvu39+ONZ21fxiTXoImr6EVZw=
  • google-site-verification=yVB-DfJkyFs3sHdr8au7wnKgM7DwVWM3Asb9XShxabM
  • onetrust-domain-verification=38675779673a409c8521c490f82beaea
  • vmware-cloud-verification-c38779a6-fe23-4e3f-8cca-92521dd790af
  • prowly-verification=bed4c199fc851c73c5810855b3529bc925b2dab77b839d92c605accccb2d3497
  • airtable-verification=ec222482f058a1f4ab5446cfa6e41a15
  • docusign=4bf0e253-ae6a-4b43-b012-2a706d148072
  • google-site-verification=pbo9mrGGQP5X8aiAUfTycXlaSuY11CzgvsMKnPeCnzQ
  • amazonses:LYZhkJ8IBDeuvlugdhTJI6amvJ9HuTu1bvrJ6gP3q8s=
  • atlassian-domain-verification=BmYUpjhrAkylIzaoWv23/zbOjICKdwTtt8Kh/aYkVRcnHkSLMrGRt/atwgLFya3A
Cloud / SaaS Services Detected
Apple Atlassian Amazon SES/WorkMail OneTrust DocuSign Proofpoint