Cuba
Hospitality / State Enterprise
Data for Sale
Gran Caribe Hotel Group Allegedly Breached, 26,000 Guest Passport Records and Full Corporate Systems Offered
An actor posting as exfilar is advertising what they describe as a complete dump of Gran Caribe Hotel Group, Cuba's largest state-owned tourism corporation, comprising 34 database backups totalling 110GB taken from production servers. The material is said to span eight hotel properties and include 26,094 guest records with full names, nationalities, passport numbers, dates of birth, and stay dates covering visitors from 70 countries, 873 employee files with salaries, national identity numbers, addresses and bank details, complete accounting and inventory systems, loyalty membership data, and guest internet accounts tied to Cuban identity numbers. The asking price is $10,000. The claim is unverified.
▣Post details
Cuba!Allegedly included
- Guest passport numbers
- Guest names & nationalities
- Dates of birth
- Check-in and check-out dates
- Room assignments & billing
- Employee salaries
- Employee bank details
- Cuban identity numbers
- Staff addresses & phone numbers
- Loyalty programme members
- Guest internet credentials
- Telecom billing records
- Security operator accounts
- Accounting & budget systems
- Supplier contracts
- Inventory & asset registers
◱Screenshots
⚠Potential impact
The passport numbers are the standout. Paired with full name, date of birth, and nationality, they form a travel-document identity set usable for account opening and document fraud, and they cannot be changed without applying for a new passport. Because the records also carry stay dates and room assignments, the set additionally establishes where identified foreign nationals were on given dates. Employee exposure is deeper still, combining salary, bank details, home address and national ID. The guest internet accounts warrant separate attention: Cuban internet access is provided through a state monopoly and tied to identity, so credentials and identity numbers together carry risk beyond ordinary account compromise.
iStatus
UnverifiedThe listing is unusually documented, with a database-by-database inventory, row counts, and samples the actor states were restored and verified. Dark Web Informer is not reproducing the sample archive location or contact routes. The stated breach date is the day before posting, indicating recent access if accurate. This is the same actor behind three separate disclosures published in the past week, operating at high tempo. Nothing has been independently corroborated. The claim is unverified and Gran Caribe has not publicly addressed it.
DARK WEB INFORMER - THREAT INTELLIGENCE