On June 20, 2026, the ransomware group RansomExx publicly listed Vietnam’s leading hourly and short-stay hotel booking platform Go2Joy (go2joy.vn) and released what it described as the platform’s complete internal database.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Go2Joy (go2joy.vn)
Get alerted the next time Go2Joy (go2joy.vn) files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Go2Joy (go2joy.vn)’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that RansomExx claims to have exfiltrated internal files during a ransomware attack on the Vietnamese company. The group posted the data on its leak site, stating it had obtained the full database of Go2Joy. No exact number of affected customer records has been confirmed, and the precise volume and sensitivity of the exposed files remain unclear from available reporting. The incident follows the group’s typical pattern of publishing victim data when ransom demands are not met.
June 20, 2026 marks the public disclosure date on the RansomExx leak site. The data includes internal files that could contain customer booking details, contact information, and other operational records tied to users who booked short-stay accommodations through the service.
Why This Matters for You and Your Family
If you or anyone in your household has ever booked a hotel room by the hour or for a short stay through Go2Joy, your personal information may now sit in a publicly accessible ransomware repository. That data can be searched, sold, or combined with other leaks to build a profile of your habits, locations, and contact details. For families, this risk extends beyond the primary account holder: shared email addresses, phone numbers used for booking confirmations, or children’s accounts linked to family devices can all become entry points for further abuse.