Cheval Blanc Randheli
bd_0e93624bbc8d2700 · schema v1 · pii pii-v1
Full breach record for Cheval Blanc Randheli →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Aurora on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
[lvmh] Guest Passport Scans — 75,855 Files, 10 Years The single largest data category: 75,855 passport scan images spanning January 2015 through October 2024, organised in daily folders within monthly and yearly directories. These represent an estimated 20,000–30,000 unique guests. Each scan contains the full passport bio page: photo, full name, date of birth, nationality, passport number, machine-readable zone (MRZ), and signature. Among the exposed passports: Qatar Royal Family members — 9 passport scans including Muhammad Mesned S M Al-Misned, Abdulla, Khalifa, Lolwa, Nasser, Alanoud, Bessy, and Mesned UAE VIP and government officials — including H.E. Ahmed Saif Ali Aldhabea Aldarmaki, H.E. Matar Suhail Ali Alyabhouni Aldhaheri, and members of an April 2024 private buyout group who arrived on private jets (tail numbers A6AUH, A6DAH) LVMH head-office executives — 7 passport/profile photos including named senior staff from Paris Guest PMS Data — 30,000–50,000 Profiles Opera PMS exports containing full names, home addresses (street-level), nationalities, VIP classification levels (A/B/C/G), partial credit card data (last-4 digits + expiry + card type), deposit amounts, booking confirmation numbers, stay histories, travel agent details, flight numbers, and guest preferences. Employee Records — 1,000–2,000 Individuals Ten years of salary records (2017–2026), medical insurance claims organised by department, ~200 ECARD ID photos, vacation/leave records, Key Management Personnel (KMP) compensation details, and biometric enrollment data from the Gladis facility-access system. Credentials and Infrastructure BitLocker recovery key — full disk-encryption key for the Windows server volume Passwords.docx — plaintext system password store covering revenue, PMS, and operational systems Extranet passwords — booking-portal and vendor credentials 3CX VoIP backup — SIP credential
Source provenance
- Source URL
- https://www.ransomware.live/id/Q2hldmFsIEJsYW5jIFJhbmRoZWxpQGF1cm9yYQ==
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 22, 2026
- Raw hash
- 46157a364986c1428a126e38a33f711b6cdc50cb2f9436e1c5b726c552e4551c
Reporting entity
- Name
- aurora
Victim entity
- Name
- Cheval Blanc Randhelinorm: cheval blanc randheli
- Domain
- chevalblanc.com
- Industry
- Hospitalityllm
What this source establishes
- Source ceiling
- A leak-site claim can't tell us: discovery date · materiality · notification · affected count · confirmed data types · compliance clock. These stay blank until a regulatory filing or victim disclosure lands.
- Attack vector
- Ransomware· aurora
- Threat actor
- AuroraExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.