ransomware Credible Mauritius (MU) hospitality

Sands Suites Resort & Spa listed by the LockBit ransomware group

Sands Suites Resort & Spa

📅 13 January 2026
CompanySands Suites Resort & Spa
Domainsands.mu
CountryMauritius (MU)
Sectorhospitality
Breach date2026-01-13
People affectedNot disclosed
Ransomware grouplockbit5
Data typesguest data, reservation records, internal documents

Overview

The LockBit ransomware group has listed Sands Suites Resort & Spa, a beachfront boutique hotel in Mauritius, on its leak site. The listing appeared on 13 January 2026.

Sands Suites Resort and Spa leak listing

What was published

The group claims to have exfiltrated data from the hotel. Hospitality operations typically hold guest profiles, reservation records and internal administrative documents, which are the likely contents of any exfiltration.

Risks for affected individuals

  • Guest personal data may be exposed.
  • Reservation and payment records could enable fraud.
  • Employees' records may be included.

What remains unknown

  • Whether data has been exfiltrated.
  • The volume of records involved.
  • The timeline of any release.

What affected people should do

Recent guests should monitor payment activity and be cautious of unsolicited messages referencing the hotel. The property should notify guests and staff, review compromised systems, and communicate the scope of the incident.

Sources

  • http://lockbitapt67g6rwzjbcxnww5efpg4qok6vpfeth7wx3okj52ks4wtad.onion/post/7144ec541db7941cc3220cb1045be9f2