On May 19, 2025, the hotel booking and operations website www.atolon-parkhotel.com appeared on the leak site of the ransomware group Stormous. Internal files containing CVs, invoices, personnel records, trainee information, 2025 reservations, and other operational documents were allegedly exfiltrated during a ransomware attack. The number of people whose personal data may have been exposed remains unknown.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
Reported Details from Reports
Public reporting indicates the data was stolen from the hotel’s internal systems and later published on the group’s dark-web leak page. The exposed material includes folders labeled “CVs,” “FACTURES,” “PERSONNELS,” “STAGIAIRES,” “RESERVATION 2025,” and references to “Hwawei.com” and “AA GROUPE 2025.” No exact count of affected individuals has been released. The primary source remains the Stormous leak site itself, indexed by ransomware.live at the onion address provided below.
Why This Matters for You and Your Family
When a hotel you booked with, applied to, or sent personal documents to suffers a breach, your name, contact details, dates of stay, and possibly payment or identification information can end up in the hands of criminals. For families this often means both parents’ employment histories, children’s travel records, and shared addresses become available for identity theft or harassment. Reservation 2025 files suggest current and upcoming travel plans may now be public, giving attackers a calendar of when homes may be empty. Even if you were not a direct guest, personnel or trainee records can expose current and former employees and their households.
The Doxxing and Identity-Chain Risk
A single leaked hotel file frequently links an email address to a real name, phone number, home address, and travel companions. Attackers then search for the same email or phone on gaming platforms, social media, and data-broker sites. This creates an identity chain that can lead to doxxing, account takeovers, or targeted scams against you or your children. Credential leaks like this one regularly cascade into gaming account compromises because kids often reuse passwords or security questions derived from family travel memories. Continuous monitoring across large breach databases is one of the few practical ways to catch these expanding chains before they reach extortion or identity theft.