Ransomware victim disclosure
← All victimsSands Suites Resort & Spa
listed as sands.mu · Claimed by LockBit · listed 4 months ago
Status timeline
- ListedFeb 14, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileSands Suites Resort & Spa is a five-star beachfront boutique hotel located on the west coast of Mauritius. The property offers luxury suites (Beachfront, Deluxe, Superior, and Exclusive), multiple dining venues, a spa, golf, watersports, and destination wedding services. It holds Green Globe certification for sustainability practices.
- Industry
- Luxury Boutique Hotel & Resort
- Address
- Mauritius (specific street address not publicly stated)
Attack summary
Severity: high — Data has been published (disclosed status: data_published) by LockBit, a prolific ransomware group. A hospitality operation of this type holds guest PII, payment card data, and booking records, representing significant personal and financial data exposure. No confirmed scale figure is available to elevate to critical.LockBit claims to have attacked Sands Suites Resort & Spa, with the disclosure status recorded as data_published, indicating that exfiltrated data has been released or made available. No specific ransom amount or data volume has been stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Guest personal information
- Booking and reservation records
- Payment and financial data
- Employee records
- Corporate communications
What the group claims
Sands Suites Resort & Spa is a tranquil beachfront boutique hotel in Mauritius that offers luxury ac...
Sources
- Victim sitesands.mu
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

