CryptoRex breaches Arkın hotel and casino data
Attackers linked to CryptoRex exfiltrated 1.4TB of guest and casino data from Arkın Group hotels in Northern Cyprus, including passports and AML/KYC records.
Cyclops Threat Intelligence reports that the Arkın Group hotel chain in Northern Cyprus, including The Arkın Colony, The Arkın Iskele, and Arkın Palm Beach with its casino, suffered a large-scale data breach. Attackers gained initial access through a compromised employee account in the reservations department, then used legitimate remote administration tools to escalate privileges, bypass network segmentation, and exfiltrate approximately 1.4 TB of data over an extended period before detection.
The stolen data includes full guest profiles with passport details, financial and payment information, internal CRM notes on VIP clients, and highly sensitive casino records covering player IDs, deposit histories, chip-exchange transactions, and KYC/AML source-of-funds documentation for high rollers. Portions of the archive have already appeared on underground forums, with segments reportedly being auctioned starting at 8 bitcoins. No formal ransom demand had been confirmed at time of reporting, suggesting a data-sale/extortion model rather than classic encryption-based ransomware.
Analysts attribute the intrusion with moderate confidence to a group tracked as "CryptoRex," active since 2023 and known for targeting hospitality and gambling businesses in the Mediterranean region. Beyond reputational damage, the breach poses acute risks: exposed VIP casino profiles could be leveraged for targeted extortion, blackmail, or physical security threats against high-net-worth individuals, while leaked AML/KYC records raise money-laundering scrutiny concerns for the jurisdiction. Affected guests are advised to reissue payment cards, monitor credit activity, and treat unsolicited contact referencing leaked personal details as a likely follow-on social engineering attempt.
Mentioned in this report
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free