Arkin Group
ent_25077d67d5c4d1047abbe5b5
Disclosures
2
Leak Site · 1 jurisdiction
Incidents
—
no linked incident in sample
Max affected reported
—
no filed count in sample
Leak-site claims
2
unverified actor claims
Identity resolution
- Canonical name
- Arkin Group
- Normalized
- arkin group— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Unverified threat-actor claim — not a regulatory filing
Attribution, victim identity, and counts shown here derive from a threat actor's public extortion-blog claims, aggregated by ransomware.live. They have not been validated by the victim or any regulator. Treat them as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Disclosure history (2)newest first
- GLOBALLeak Siteas victim2026-06-30
CYBERSECURITY: ARKIN HOTEL GROUP SUFFERS MASSIVE DATA BREACH — OVER 1 TB OF GUEST AND CASINO DATA STOLENCybersecurity experts from Cyclops Threat Intelligence have reported a critical incident affecting the Arkın Group hotel chain (www.arkingroup.com), including its premium properties The Arkın Colony, The Arkın Iskele, and Arkın Palm Beach in Northern Cyprus. According to preliminary assessments, the attackers managed to exfiltrate over one terabyte of internal documents, customer databases, and transaction logs, including confidential information from the Arkın Palm Beach Casino.▎Attack detailsAnalysts have established that the attackers gained initial access through a compromised employee account in the reservations department. Using legitimate remote administration tools, they gradually expanded their privileges, bypassed network segmentation, and exfiltrated a dataset totalling approximately 1.4 TB. Some of the stolen information has already surfaced on underground forums and darknet marketplaces.The stolen data includes:• Full guest profiles (passport details, phone numbers, addresses, stay history);• Financial details of bookings and payment credentials;• The internal CRM system with staff notes on VIP clients;• Casino database: player IDs, deposit amounts, visit frequency, records of chip exchange transactions and fund movements;• Scanned passports, compliance check forms (KYC/AML), including source-of-funds questionnaires for high rollers.▎Objective and likely operatorBased on the intrusion characteristics and tactics used, experts link the incident to the threat group “CryptoRex” (tracked since 2023), which specialises in attacking hospitality and gambling businesses in the Mediterranean region. A combination of financial extortion and data sale to multiple buyers is considered likely. So far, no official ransom demand has been received, but portions of the
- GLOBALLeak Siteas victim2026-06-30
CYBERSECURITY: ARKIN HOTEL GROUP SUFFERS MASSIVE DATA BREACH — OVER 1 TB OF GUEST AND CASINO DATA STOLENCybersecurity experts from Cyclops Threat Intelligence have reported a critical incident affecting the Arkın Group hotel chain (www.arkingroup.com), including its premium properties The Arkın Colony, The Arkın Iskele, and Arkın Palm Beach in Northern Cyprus. According to preliminary assessments, the attackers managed to exfiltrate over one terabyte of internal documents, customer databases, and transaction logs, including confidential information from the Arkın Palm Beach Casino.▎Attack detailsAnalysts have established that the attackers gained initial access through a compromised employee account in the reservations department. Using legitimate remote administration tools, they gradually expanded their privileges, bypassed network segmentation, and exfiltrated a dataset totalling approximately 1.4 TB. Some of the stolen information has already surfaced on underground forums and darknet marketplaces.The stolen data includes:• Full guest profiles (passport details, phone numbers, addresses, stay history);• Financial details of bookings and payment credentials;• The internal CRM system with staff notes on VIP clients;• Casino database: player IDs, deposit amounts, visit frequency, records of chip exchange transactions and fund movements;• Scanned passports, compliance check forms (KYC/AML), including source-of-funds questionnaires for high rollers.▎Objective and likely operatorBased on the intrusion characteristics and tactics used, experts link the incident to the threat group “CryptoRex” (tracked since 2023), which specialises in attacking hospitality and gambling businesses in the Mediterranean region. A combination of financial extortion and data sale to multiple buyers is considered likely. So far, no official ransom demand has been received, but portions of the