Ransom! Ark,ın Group / Arkın Casino, The Arkın Colony, The Arkın Iskele, and Arkın Palm Beach (AUG-2026)

Ransom! Ark,ın Group / Arkın Casino, The Arkın Colony, The Arkın Iskele, and Arkın Palm Beach (AUG-2026)
Blacknevas has allegedly breached Arkın Group in Turkey, compromising Arkın Group/Arkın Casino and the Arkın Colony, Arkın Iskele, and Arkın Palm Beach properties and exfiltrating over 1 TB of guest, casino, and internal CRM data. The attacker reportedly used a compromised employee reservations account to expand access, bypass segmentation, and steal passport/KYC-AML records and transaction/player information from TR facilities. #Turkey

Incident Details

Information

  • Over 1 TB of guest, internal, and casino data was stolen from the Arkın hotel group, with some archives already appearing on underground forums and darknet marketplaces.
  • Attackers reportedly entered through a compromised reservations employee account, then used legitimate remote administration tools to expand access and bypass segmentation.
  • The leaked material includes full guest profiles, booking and payment information, staff CRM notes, casino player records, chip exchange and fund movement logs, and scanned passports with KYC/AML documents.
  • Security analysts link the intrusion to the threat group CryptoRex, known for targeting hospitality and gambling businesses in the Mediterranean region.
  • The incident appears to involve both extortion and resale of the stolen data, with parts of the archive reportedly offered for auction starting at 8 bitcoins.
  • The exposure of VIP and casino client records creates serious personal safety risks, including extortion, kidnapping, and blackmail.
  • Stolen payment details could enable fraudulent transactions, phishing, and card abuse, especially given the high spending limits associated with casino patrons.
  • The breach may trigger legal and regulatory consequences, including lawsuits from affected guests and scrutiny from payment networks and compliance bodies.
  • Exposed AML and source-of-funds records could prompt money-laundering investigations and increased oversight of the jurisdiction’s gambling sector.
  • The incident is expected to cause long-term reputational damage to the Arkın brand and may drive wealthy clients toward competing luxury destinations.
  • Affected individuals are advised to reissue bank cards, monitor credit reports, enable additional authentication, and treat suspicious calls or messages as potential targeted attacks.
  • The company has not yet publicly responded, online booking is temporarily unavailable, and authorities have begun consultations with EU experts.

Disclaimer: This post is based on public claims made by the ransomware group "blacknevas". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live