On March 25, 2025, the luxury Caribbean resort Curtain Bluff appeared on the leak site of the medusalocker ransomware group. Vacationers’ personal data, years of audit records, bank statements showing every transaction, internal documents including menus, and roughly 500 unique login and password pairs were allegedly exfiltrated and listed for sale at a $120,000 ransom.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Curtain Bluff
Get alerted the next time Curtain Bluff files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Curtain Bluff’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Available reporting describes the breach as a classic ransomware incident in which attackers gained access, encrypted systems, and exfiltrated sensitive files before publishing a sample on their dark-web portal. The data set includes guest personal information, historical financial records, and operational files that would normally remain private. Public reporting indicates the group also obtained approximately 500 credential pairs that could unlock additional accounts tied to the resort or its guests. No confirmed victim count for individual guests has been released, but the nature of a resort booking system means names, addresses, phone numbers, payment details, and travel dates are likely included.
The listing appeared on the medusalocker leak site, hosted on an onion address and tracked by ransomware.live. As of the publication date, the files remain available to anyone willing to pay the demanded sum.
Why This Matters for You and Your Family
If you or anyone in your family has stayed at Curtain Bluff, your personal information may now sit inside a ransomware data package. Bank statements reveal spending patterns, account numbers, and transaction histories that fraudsters can use for identity theft or targeted scams. Login and password pairs create immediate risk: once one credential is exposed, attackers test it across email, social media, and financial sites in hopes of taking over additional accounts.