Arkın Group Listed by blacknevas Ransomware Group
If you are a customer of Arkın Group, here’s what is being claimed, and what it would mean for you.
CYBERSECURITY: ARKIN HOTEL GROUP SUFFERS MASSIVE DATA BREACH — OVER 1 TB OF GUEST AND CASINO DATA STOLENCybersecurity experts from Cyclops Threat Intelligence have reported a critical incident affecting the Arkın Group hotel chain (www.arkingroup.com), including its premium properties The Arkın Colony, The Arkın Iskele, and Arkın Palm Beach in Northern Cyprus. According to preliminary assessments, the attackers managed to exfiltrate over one terabyte of internal documents, customer databases, and transaction logs, including confidential information from the Arkın Palm Beach Casino.▎Attack deta
— from Blacknevas’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
On July 14, 2026, the Arkın Group hotel chain operating in Northern Cyprus appeared on the leak site of the blacknevas ransomware group. The listing states that attackers exfiltrated more than one terabyte of internal files during a ransomware incident that struck the company’s properties, including The Arkın Colony, The Arkın Iskele, and Arkın Palm Beach. Anyone who has stayed at these hotels, gambled at the Arkın Palm Beach Casino, or provided personal details for reservations or loyalty programs may have their information now in criminal hands.
Watch Arkın Group
Get alerted the next time Arkın Group files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Arkın Group’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals — $499/mo or $4,990/yr (indicative estimate).
Primary Disclosure Details
The blacknevas leak site, accessible via the onion address published on ransomware.live, lists Arkın Group under its active extortion page. The entry states that internal files were exfiltrated and threatens publication unless the company meets undisclosed demands. The disclosure does not specify the exact number of affected individuals, nor does it itemize every record type beyond noting customer databases, transaction logs, and casino-related documents. No sample data has been publicly released on
What the free scan actually returns These listings are live, public, and legal to remove — and removing them is what we do. Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified. Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.Found on people-search siteswe remove these
Found in breach recordsverifiedreported — unverified
Report details & sourcing
Related breaches
Agrimac Listed by Storm Ransomware Group
Agrimac achieves Australian first - Agrimac is the first agricultural dealership in Australia to be …
Zion Construction Listed by thegentlemen Ransomware Group
zionconstructioninc.com Zion Construction Inc is a reputable general contracting and home building c…
Servifruit Listed by medusalocker Ransomware Group
Organization with 195 emails extracted. Domain: servifruit.com…