On March 13, 2026, the SAS CAP ESTEL HOTEL appeared on the leak site operated by the nightspire ransomware group. The hospitality company’s internal files were allegedly exfiltrated during a ransomware attack, and the group has now made the stolen data publicly available.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
What Public Reporting Shows
Public reporting indicates that nightspire listed the French hotel on its leak site on March 13, 2026. The data consists of internal files exfiltrated after the ransomware operators gained access to the hotel’s systems. The exact number of people whose information may have been exposed remains unknown, and the specific types of records have not been detailed in available reporting. The incident follows the group’s typical pattern of stealing data before encrypting systems and then threatening to publish it if ransom demands are not met.
Why This Matters for You and Your Family
When a hotel suffers a breach, the information stolen often includes guest records, reservation details, payment information, and staff payroll or HR files. If your family has stayed at SAS CAP ESTEL HOTEL or used its services, your names, addresses, phone numbers, email addresses, or payment card data could be among the records now circulating. Credential leaks like this one frequently cascade into account takeovers on other sites where you reuse the same email and password combination. Children’s accounts tied to family email addresses are especially vulnerable because gaming platforms and social apps rarely enforce strong authentication.
The Doxxing and Identity-Chain Implications
Once internal files leave a company’s control, attackers and opportunistic criminals can link seemingly harmless details into a complete picture of your life. A hotel booking might contain your home address, travel dates, and companion names. That information can be cross-referenced with breached credentials from other services to map your online handles to your real identity. The result is a doxxing chain that can lead to harassment, targeted scams, or identity theft affecting every member of your household. Public reporting describes how such chains often begin with one seemingly minor breach and expand rapidly when data brokers and underground forums sell the combined information.