companion allegedly hacked as reported by african-american Nevas ransomware: CYBERSECURITY: ARKIN HOTEL group SUFFERS MASSIVE data breach OVER 1 tuberculosis OF GUEST AND CASINO data STOLENCybersecurity experts from Cyclops threat Intelligence have reported a critical incident affecting the Ark1n group hotel chain ( including its premium properties The Ark1n Colony, The Ark1n Iskele, and Ark1n palm Beach in Northern Cyprus. According to preliminary assessments, the attackers managed to exfiltrate over one tebibyte of internal documents, customer databases, and dealing logs, including confidential information from the Ark1n palm Beach Casino.�Attack detailsAnalysts have established that the attackers gained initial access through a compromised employee account in the reservations department. Using legitimate remote administration tools, they gradually expanded their privileges, bypassed network segmentation, and exfiltrated a dataset totalling approximately 1.4 TB. Some of the stolen information has already surfaced on underground forums and darknet marketplaces.The stolen data includes:" Full guest profiles (passport details, phone numbers, addresses, stay history);" Financial details of bookings and payment credentials;" The internal CRM system with staff notes on VIP clients;" Casino database: player IDs, deposition amounts, visit frequency, records of chip exchange transactions and fund movements;" Scanned passports, submission mark forms (KYC/AML), including source-of-funds questionnaires for high rollers.�Objective and likely operatorBased on the intrusion characteristics and tactics used, experts link the incident to the threat group CryptoRex (tracked since 2023), which specialises in attacking hospitality and gambling businesses in the Mediterranean region. a combining of financial extortion and data sale to multiple buyers is considered likely. so far, no official ransom demand has been received, but portions of the archives have been put up for auction with a starting toll of 8 bitcoins.�Potential consequences of the leakThe leakage of confidential guest and especially casino client data entails a cascade of risks that tour far beyond reputational damage.1. Personal surety of high-net-worth guestsThe VIP casino player database, containing passport details, habits, and financial capabilities, serves as a direct directory for kidnappers, extortionists, and organised crime groups. Affected individuals may face real threats to their physical safety, as well as targeted blackjack (e.g., threats to expose gambling activity to business partners or family members in countries where gambling is stigmatised).2. Financial fraudPayment data from hotel guests and credit/debit cards linked to casino accounts will enable unauthorised transactions. Given the high credit limits of casino patrons, the scale of potentiality phishing and card fraudulence is assessed as very significant.3. complaisance nightmare and regulatory finesAlthough the international casino operators in Northern Cyprus come not directly pass under GDPR, many guests are citizens of the EU, the UK, and CIS countries. The breach demonstrates a flagrant failure to meet personal data protection standards. Lawsuits by affected individuals in national courts and scrutiny by international payment systems (Visa, Mastercard) are possible, which could suspend acquiring services.4. Risks to the casino itself and the jurisdiction6/9/2026 1:09 PM ChatGPT 5 | Deepseek | Claude: The exposure of internal AML records documenting the origin of funds and possible links to politically exposed persons could spark money-laundering investigations. For Northern Cypruss gambling zone, already under close vigil by the FATF, this could lead to tighter international financial monitoring and being placed on grey lists.5. Reputational ruinNo wealthy node will entrust their data to a hotel incapable of protecting basic IT infrastructure. trust in the Ark1n brand, which for decades has built an image of secluded luxury, will be undermined for years. Competitors in the elite leisure market, especially in Dubai, Monaco, and the Maldives, will immediately work the situation to poach wary clientele.�Analysts recommendationsCyclops threat intelligence strongly advises all individuals who have ever stayed at Ark1n hotels or visited Ark1n palm Beach Casino to:" Immediately block and reissue any cant cards used;" monitor credit reports for new applications;" Enable additional certification factors on email and financial services;" be highly critical of any incoming calls or messages demanding identity confirmation or fund transfers these could be targeted attacks using contextual details from the leaked staff notes.The Ark1n group press office has not yet responded to official inquiries. The companys website remains operational, but online booking sections are temporarily unavailable. Northern Cyprus authorities stated that they are aware of the incident and have begun consultations with eu experts under a cyber-resilience programme.Report prepared by the Thomson Reuters cybersecurity desk based on the Cyclops terror Intelligence analytical brief.