Ransomware victim disclosure
← All victimsCopamarina Beach Resort
Claimed by Thegentlemen · listed 4 months ago
Status timeline
- ListedFeb 15, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Country
- Puerto Rico
- Sector
- Hospitality and Tourism
- Listed on leak site
- Feb 15, 2026
About the victim
AI dossier — public-source company profileCopamarina Beach Resort & Spa is a beachfront resort located in Guánica, Puerto Rico, set on 20 acres of tropical gardens along Puerto Rico's southwestern coast. The property offers multiple room categories, luxury villas, on-site restaurants, a spa, and over 20,000 square feet of indoor/outdoor event space. It caters to leisure travelers, families, weddings, and corporate events.
- Industry
- Hospitality & Resort
- Address
- PR-333 KM 6.5, Guánica, Puerto Rico
Attack summary
Severity: medium — Status is data_published indicating some data was released, but the leak post content is inaccessible (bot-check wall), no ransom amount or data size is stated, and no specific regulated data (e.g., medical or government) is confirmed; hospitality PII exposure warrants medium severity.The group 'thegentlemen' claims a data publication (disclosed status: data_published) against Copamarina Beach Resort; the leak post itself was blocked by a bot-verification page, so specific claims about encryption or exfiltration volume cannot be confirmed from the post content.
Data the group says was taken
AI dossier — extracted from the leak post- Guest personal information
- Booking and reservation records
- Payment or financial data
- Employee records
- Corporate/event client data
What the group claims
copamarina.com zoominfo.com/c/copamarina-beach-resort/1146144172 Discover your ideal vacation at Copamarina Beach Resort and Spa! Book your stay at our beautiful oceanfront hotel destination in Guanica, Puerto Rico.
The leak post
captured from the group's siteGentlecloud Protection 🛡️ Gentlecloud Verifying your browser... Initializing security checks... I'm not a bot
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

