Ransomware victim disclosure
← All victimsM'AR De AR Hotels
Claimed by Nitrogen · listed 1 year ago
Status timeline
- ListedApr 25, 2025
- Data leakeddate unknown
At a glance
- Group
- Nitrogen
- Status
- Data leaked
- Country
- Portugal
- Sector
- Hospitality and Tourism
- Listed on leak site
- Apr 25, 2025
About the victim
AI dossier — public-source company profileM'AR De AR Hotels is a Portuguese boutique hotel group operating three charming properties in Évora and Lisbon. The group specializes in luxury accommodations with personalized service, spa & wellness facilities, fine dining, and event spaces, targeting leisure and business travelers seeking authentic regional experiences.
- Industry
- Luxury Hospitality & Hotels
- Address
- Évora and Lisbon, Portugal (multiple locations: M'AR De AR Aqueduto in Évora, M'AR De AR Muralhas in Évora, M'AR De AR Auria in Lisbon)
Attack summary
Severity: medium — Data published with no ransomware proof files, ransom demand, or technical evidence provided. Hospitality sector breach affects guest PII and booking data, but lack of proof or operational impact details prevents higher rating.Nitrogen group claims to have compromised M'AR De AR Hotels and published data. The leak post provides no detail on what data was exfiltrated, whether systems were encrypted, or the scope of the breach.
Data the group says was taken
AI dossier — extracted from the leak post- guest records
- booking information
- business operations data
What the group claims
M'AR De AR Hotels is a hotel group in Portugal, offering a range of accommodations primarily in the southern region of the country. The group aims to deliver a luxurious yet comfortable experience for guests, with a focus on personalized service, elegant designs, and proximity to key tourist destinations.
Screenshot of the leak post

Sources
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

