On March 12, 2025, the internal server of Marina Bay Sands in Singapore appeared on the leak site of the Babuk2 ransomware group. The listing indicates that attackers exfiltrated internal files during a ransomware incident at the luxury hotel and casino operator. While the exact number of people affected remains unknown, anyone whose personal information passed through the resort’s systems — guests, loyalty program members, employees, or vendors — could have data now in attackers’ hands.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Marina Bay Sands
Get alerted the next time Marina Bay Sands files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Marina Bay Sands’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting on the Babuk2 leak site describes the compromise of an internal server belonging to marinabaysands.com. The posting, dated March 12, 2025, states that files were successfully exfiltrated. No sample data has been publicly released at the time of writing, and the precise volume or sensitivity of the stolen information has not been disclosed by the hotel. Available reporting describes the incident as a ransomware attack in which the group first gained access, encrypted systems, and then threatened to publish the stolen files unless a ransom was paid.
Why This Matters for You and Your Family
When a major hospitality company loses control of internal files, the ripple effects reach ordinary guests and staff. Booking details, contact information, payment records, and employee documents can contain exactly the pieces of data that identity thieves need. For your family this means heightened risk of phishing emails that look legitimate because they reference a real stay, unexpected credit-card charges, or fraudulent accounts opened in your name. Children’s information linked to family bookings can also surface, creating long-term exposure that follows them into adulthood.
The Doxxing and Identity-Chain Implications
A single breach rarely stays isolated. Internal files often contain email addresses, phone numbers, dates of birth, and sometimes passport copies — data that attackers combine with information from previous leaks. This creates an identity chain: one exposed credential leads to account takeovers on travel sites, loyalty programs, and email, which in turn reveal more personal details. Gaming accounts belonging to you or your children are especially vulnerable because the same passwords and recovery emails are frequently reused. Once attackers link a gamer tag to a real identity and home address, harassment and doxxing become practical threats.