On May 16, 2025, the Nissi Beach Resort in Ayia Napa, Cyprus, appeared on the leak site of the incransom ransomware group. The hospitality company, which employs 283 people and generates roughly $10 million in annual revenue, had 400GB of internal files exfiltrated during a ransomware attack.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch nissi-beach.com
Get alerted the next time nissi-beach.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about nissi-beach.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates the attackers published a sample of the stolen data on their onion site and listed the resort as a victim. The exposed material includes internal files; exact contents have not been independently verified by third parties. The resort’s publicly listed phone numbers — +357 23721021 and +357 23 722 900 — appear alongside the disclosure, as does a reference to the domain alion.com. No confirmed count of affected guests or employees has been released, leaving thousands of past and present visitors uncertain whether their reservations, contact details, or payment records were inside the 400GB archive.
Why This Matters for You and Your Family
When a hotel you trusted with your holiday plans, passport copy, or credit-card details suffers a breach, the risk does not stop at the company. Your personal information can surface on dark-web markets, get bundled into larger data sets, and be used for identity theft, phishing, or harassment. For families, a single leaked booking can expose children’s names, dates of birth, and even email addresses tied to school or gaming accounts. Once that information is loose, it is nearly impossible to retract. The May 16, 2025 disclosure is a concrete reminder that even a relaxing beach resort can become a gateway to long-term privacy headaches for ordinary travellers.
The Doxxing and Identity-Chain Implications
Ransomware leaks rarely contain just one type of record. A hotel booking often links your name, home address, phone number, email, and sometimes travel companions. Attackers and subsequent buyers can chain these pieces together with data from other breaches to build a full profile. Public reporting describes how such chains frequently lead to doxxing, targeted scams, or takeovers of connected online accounts. Gaming usernames belonging to you or your children are especially vulnerable because kids often reuse email addresses or passwords from family bookings. A credential leak like this one can cascade into account takeovers that expose chat logs, friend lists, and location data.