Arkin Group
bd_933840f56d99f5c1 · schema v1 · pii pii-v1
Full breach record for Arkin Group →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Blacknevas on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
CYBERSECURITY: ARKIN HOTEL GROUP SUFFERS MASSIVE DATA BREACH — OVER 1 TB OF GUEST AND CASINO DATA STOLENCybersecurity experts from Cyclops Threat Intelligence have reported a critical incident affecting the Arkın Group hotel chain (www.arkingroup.com), including its premium properties The Arkın Colony, The Arkın Iskele, and Arkın Palm Beach in Northern Cyprus. According to preliminary assessments, the attackers managed to exfiltrate over one terabyte of internal documents, customer databases, and transaction logs, including confidential information from the Arkın Palm Beach Casino.▎Attack detailsAnalysts have established that the attackers gained initial access through a compromised employee account in the reservations department. Using legitimate remote administration tools, they gradually expanded their privileges, bypassed network segmentation, and exfiltrated a dataset totalling approximately 1.4 TB. Some of the stolen information has already surfaced on underground forums and darknet marketplaces.The stolen data includes:• Full guest profiles (passport details, phone numbers, addresses, stay history);• Financial details of bookings and payment credentials;• The internal CRM system with staff notes on VIP clients;• Casino database: player IDs, deposit amounts, visit frequency, records of chip exchange transactions and fund movements;• Scanned passports, compliance check forms (KYC/AML), including source-of-funds questionnaires for high rollers.▎Objective and likely operatorBased on the intrusion characteristics and tactics used, experts link the incident to the threat group “CryptoRex” (tracked since 2023), which specialises in attacking hospitality and gambling businesses in the Mediterranean region. A combination of financial extortion and data sale to multiple buyers is considered likely. So far, no official ransom demand has been received, but portions of the
Source provenance
- Source URL
- https://www.ransomware.live/id/QXJraW4gR3JvdXBAYmxhY2tuZXZhcw==
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 30, 2026
- Raw hash
- 9945d12d30a8bbcde0797851911405c0d84ceae5bc843c577308c86403e8ca25
Reporting entity
- Name
- blacknevas
Victim entity
- Name
- Arkin Groupnorm: arkin group
- Industry
- Professional Servicesllm
What this source establishes
- Source ceiling
- A leak-site claim can't tell us: discovery date · materiality · notification · affected count · confirmed data types · compliance clock. These stay blank until a regulatory filing or victim disclosure lands.
- Attack vector
- Ransomware· blacknevas
- Threat actor
- BlacknevasExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.