On July 2, 2026, the Holiday Palace Hotel in Spain appeared on the leak site of the ransomware group apt73. The attackers published proof that they had exfiltrated internal files containing guest information, documents, reports, photos, and videos. The number of people affected remains unknown, but anyone who has stayed at the hotel or whose details were stored in its systems could have personal data now circulating among criminals.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch holidaypalace.com
Get alerted the next time holidaypalace.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about holidaypalace.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that apt73 gained access to the hotel’s network, encrypted systems, and then exfiltrated data before demanding payment. The group listed Holiday Palace Hotel on its dark-web leak page on July 2, 2026, and provided samples of the stolen material. Available reporting describes the exposed information as including guest records, internal business documents, staff reports, and media files such as photographs and videos. No exact count of records or victims has been released by the hotel or the attackers.
Why This Matters for You and Your Family
When a hotel you trusted suffers a breach, your personal details can end up in the hands of extortionists. Guest information often includes full names, home addresses, phone numbers, email addresses, dates of stay, and sometimes payment card details or passport copies. Criminals can use this to attempt identity theft, craft convincing phishing messages, or sell the data on underground forums. For families, a single breach can expose both parents and children if bookings were made under one reservation. The July 2, 2026 listing means the clock is already running on how quickly that information spreads.
The Doxxing and Identity-Chain Implications
Stolen hotel records rarely stay isolated. A name and email from a booking can be cross-referenced with social-media accounts, gaming usernames, or family photos that appear in the leaked videos and images. This creates an identity chain that links your online handles to your real-world address and family members. Once criminals map these connections, they can target you with harassment, SIM-swapping attacks, or coordinated doxxing campaigns. Credential leaks of this nature frequently cascade into account takeovers on other services where the same email or password was reused, including gaming platforms used by children.