On April 9, 2025, Canadian Rocky Mountain Resorts appeared on the leak site of the ransomware group World Leaks. The company, which operates hotels and hospitality services in Banff, Lake Louise, and Moraine Lake, is claimed to have had internal files exfiltrated during a ransomware attack. Public reporting indicates that the precise number of affected guests remains unknown, but anyone who has stayed at or done business with these properties could have personal information now at risk.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
What Public Reporting Shows
The incident involves the theft of internal documents rather than a direct compromise of an online booking database. Available reporting describes the data as internal files, though the exact contents have not been independently verified by third parties. The listing on the World Leaks site follows the group’s standard practice of publishing samples or announcing data availability after an organization declines to pay a ransom. No confirmed evidence has surfaced yet showing large-scale customer records such as credit card numbers, but the nature of hospitality operations means guest names, addresses, phone numbers, email addresses, and reservation details are likely present in internal systems.
April 9, 2025 marks the public disclosure date on the leak site. The ransomware operators typically set payment deadlines measured in days or weeks; however, specific deadlines for this case have not been publicly detailed in available reporting.
Why This Matters for You and Your Family
If you or your family have ever booked a stay, attended an event, or provided contact information to Canadian Rocky Mountain Resorts, your details may now sit in a ransomware operator’s archive. Hospitality companies routinely collect home addresses, phone numbers, email accounts, and sometimes passport or driver’s license copies for international guests. Once that information leaves the company’s control, it can be sold, traded, or used to launch further attacks against you.