Ransomware victim disclosure
← All victimsSAS CAP ESTEL HOTEL
Claimed by Nightspire · listed 3 months ago
Status timeline
- ListedMar 22, 2026
- Data leakeddate unknown
At a glance
- Group
- Nightspire
- Status
- Data leaked
- Country
- France
- Sector
- Hospitality and Tourism
- Listed on leak site
- Mar 22, 2026
About the victim
AI dossier — public-source company profileCap Estel is a 5-star luxury boutique hotel located on a two-hectare private peninsula in Eze-Bord-de-Mer on the French Côte d'Azur, near Monaco. The property features 20 rooms and suites, a Michelin-starred restaurant (La Table du Cap Estel), a Sothys spa, two sea-view swimming pools, and a private beach. It operates as an intimate, high-end establishment catering to an exclusive international clientele.
- Industry
- Luxury Boutique Hotel & Fine Dining
- Address
- Avenue Raymond Poincaré, Eze-Bord-de-Mer, France
- Employees
- 11-50
Attack summary
Severity: high — Data is listed as published by the group, indicating confirmed exfiltration. A luxury hotel handling high-net-worth international guests likely holds significant PII, payment card data, and reservation records, warranting a high severity classification. Insufficient detail to confirm regulated medical or government data that would elevate to critical.The Nightspire ransomware group claims to have attacked SAS Cap Estel Hotel and lists the disclosure status as data_published, indicating exfiltration and/or publication of data. The specific contents of the published data are not detailed in the available leak post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Guest personal information
- Reservation and booking records
- Financial and payment data
- Employee records
- Corporate/event client data
What the group claims
Data is not available now.
Sources
- Victim sitewww.capestel.com/en
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

