ShellCodeX
Tools β€’ Events β€’ News β€’ Insights
Victim Claim

Cheval Blanc Randheli

aurora πŸ‡²πŸ‡» MV Hospitality and Tourism chevalblanc.com
Claimed by aurora
Listed on leak site 29 Apr 2026
Reported attack date 22 Apr 2026
Group claims tracked 21
Unverified claim. This entry reproduces a listing published by the aurora group on its own extortion site. Attackers routinely exaggerate or fabricate victims. Nothing here confirms that Cheval Blanc Randheli suffered a breach, or what data was actually taken.

About the organisation

[lvmh] Guest Passport Scans β€” 75,855 Files, 10 Years The single largest data category: 75,855 passport scan images spanning January 2015 through October 2024, organised in daily folders within monthly and yearly directories. These represent an estimated 20,000–30,000 unique guests. Each scan contains the full passport bio page: photo, full name, date of birth, nationality, passport number, machine-readable zone (MRZ), and signature. Among the exposed passports: Qatar Royal Family members β€” 9 passport scans including Muhammad Mesned S M Al-Misned, Abdulla, Khalifa, Lolwa, Nasser, Alanoud, Bessy, and Mesned UAE VIP and government officials β€” including H.E. Ahmed Saif Ali Aldhabea Aldarmaki, H.E. Matar Suhail Ali Alyabhouni Aldhaheri, and members of an April 2024 private buyout group who arrived on private jets (tail numbers A6AUH, A6DAH) LVMH head-office executives β€” 7 passport/profile photos including named senior staff from Paris Guest PMS Data β€” 30,000–50,000 Profiles Opera PMS exports containing full names, home addresses (street-level), nationalities, VIP classification levels (A/B/C/G), partial credit card data (last-4 digits + expiry + card type), deposit amounts, booking confirmation numbers, stay histories, travel agent details, flight numbers, and guest preferences. Employee Records β€” 1,000–2,000 Individuals Ten years of salary records (2017–2026), medical insurance claims organised by department, ~200 ECARD ID photos, vacation/leave records, Key Management Personnel (KMP) compensation details, and biometric enrollment data from the Gladis facility-access system. Credentials and Infrastructure BitLocker recovery key β€” full disk-encryption key for the Windows server volume Passwords.docx β€” plaintext system password store covering revenue, PMS, and operational systems Extranet passwords β€” booking-portal and vendor credentials 3CX VoIP backup β€” SIP credentials, extension configurations, call routing rules Biometric templates (Gladis enrollment) β€” non-rotateable fingerprint/facial data Corporate-Sensitive Documents Management Contract of Cheval Blanc Randheli β€” the LVMH–property owner agreement containing fee structures, performance benchmarks, and brand license terms Board investment recommendation for Velidhoo β€” a potential new property with capital allocation and return projections 10 years of budgets and revenue forecasts Audited subsidiary financial statements (I&T / Sitax entities) White Book β€” the property's operational standards manual (proprietary LVMH brand IP) Building Management System data β€” HVAC, power, desalination, and lighting control files for island infrastructure

What the listing means

Cheval Blanc Randheli appeared on the aurora leak site on 29 April 2026. Groups publish a victim once negotiations stall or as pressure during them, so a listing usually means data was already exfiltrated β€” the attack itself is dated 22 April 2026, 7 days before the listing. This group has published 1 claim in the last 30 days and remains active.

Recommended actions

  • Treat any unsolicited message referencing Cheval Blanc Randheli as suspicious β€” leaked data gets weaponised for phishing within days.
  • If you hold an account on chevalblanc.com, change that password now, update it anywhere you reused it, and enable two-factor authentication.
  • Other Hospitality and Tourism organisations should review this group's known TTPs and validate detection coverage against them.
  • Watch for follow-on extortion: stolen data is often re-leaked or resold after the initial listing.
  • A leak-site listing is a claim made by the attacker, not a confirmed breach β€” check the organisation's own disclosures before acting on it.

Leak-site evidence

Listing URL https://www.ransomware.live/id/Q2hldmFsIEJsYW5jIFJhbmRoZWxpQGF1cm9yYQ==

Show leak-site screenshot

Captured from the group's extortion site. It may contain the victim's data or the attacker's messaging.

Screenshot of the aurora leak-site listing for Cheval Blanc Randheli