On December 14, 2025, the Hyatt Place New York / Chelsea Hotel appeared on the leak site of the nightspire ransomware group, with the attackers claiming to have exfiltrated internal files during a ransomware incident.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Hyatt Place New York / Chelsea
Get alerted the next time Hyatt Place New York / Chelsea files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Hyatt Place New York / Chelsea’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates the hotel was listed on the nightspire leak portal, which is tracked by ransomware.live. The entry states that internal files were taken during the attack, although the exact number of affected individuals remains unknown. No specific details about the volume or exact nature of the stolen data have been publicly released by the hotel or the group. The listing follows the typical pattern in which ransomware operators first demand payment and then publish samples or announcements when victims do not meet their deadlines.
Why This Matters for You and Your Family
When a hotel you or your family have stayed at suffers a breach, your personal information may be among the internal files now in criminal hands. Reservation records, payment details, email addresses, phone numbers, and physical addresses are common in hospitality systems. Even if you were not directly notified, the exposure can still affect you months or years later when criminals piece together enough fragments to target your accounts or identity. For families this risk extends to every member who has ever provided information during a booking, including children whose details sometimes appear in loyalty programs or family reservations.
The Doxxing and Identity-Chain Risks
Stolen hotel records rarely stay isolated. A single email or phone number can link your gaming usernames, social-media handles, and family addresses into a complete profile. Criminals use these chains to move from one compromised account to the next, turning a hotel breach into broader identity theft, account takeovers, or targeted harassment. Credential leaks like this one frequently cascade into gaming platforms, where children’s accounts become entry points for further extortion or doxxing because the same password or recovery email was reused.