Wednesday 9 Sep, 2026

After the attack on Stordalen hotel – hackers leak sensitive data

Remove

The saga surrounding Petter Stordalen's hotel chain Nordic Choice – which has been the victim of a so-called ransomware attack – continues. Now, the blackmailers have published passport copies and salary information from Swedish hotels on the dark web.

Over the weekend, Finnish security expert Mikko Hypponen drew attention to on Twitter that passport copies from Nordic Choice have started to leak onto the dark web, which is a kind of alternative and anonymized internet. Since then, more information has been published by the attackers, according to the magazine Ny Teknik.  

It should In addition to passport copies of several employees in the group, there are thousands of files that come from the chain's Swedish payroll system, which includes around 60 Swedish hotels. There are documents from 2015 onwards with salary specifications for thousands of employees with sensitive information such as social security numbers, address details and bank account details, as well as lists of company cars, holiday schedules and employment contracts and bonus terms for managers, writes Ny Teknik. 

Di has been in contact with Nordic Choice, who do not want to be interviewed about the data. Instead, they answer questions via email.

”"We are aware of the leak, which unfortunately confirms how hackers work after such an attack and how they ruthlessly publish the stolen information online. They are now trying to increase the pressure on us to pay them, which we will not do. From similar incidents against other companies, it is clear that we cannot trust that the data they have stolen will not be sold on or published later. We have had no dialogue with the attackers," writes Nordic Choice Hotels' communications advisor Jonathan Blom.

It was during the night of December 2 that the cyber attack against Nordic Choice was discovered. A total of 200 hotels in five countries were affected by the virus, which has affected booking, check-in and check-out, and payment solutions.

”"We have an ongoing dialogue with the Norwegian Data Protection Authority about notifying those affected by the leak. We also have a dialogue with the police who are assisting us in our work. This is a process that is still ongoing. We have great understanding that this creates frustration and anger among those affected," continues Jonathan Blom.

Nordic Choice does not want to answer any follow-up questions regarding the matter.

”"Our ambition is to be open and share information and tell more in depth about the attack after we are done securing systems and cleaning up. We believe it is in everyone's interest that we are open so that we as a society can help each other stand united together against criminal activities," writes Jonathan Blom.

Earlier this summer, several of the grocery chain Coop's stores in Sweden were hit by a similar attack. They were forced to remain closed because their cash register system was not working.

Source: DI.SE

Remove

Related posts

After several years of rapid growth, tourism in Iceland appears to have stabilized around...
Interest in WTM London 2026 is already high several months before the fair. The organizer states that...
Monaco is one of the world's smallest countries, but it contains an unusually large mix of history,...
Sunsets, long dinners and an escape from the hustle and bustle of everyday life. A vacation can do more for your relationship...

Popular posts

Our website uses cookies. Read more about our use of cookies: Privacy policy