RANSOMWARE VICTIMHOSPITALITY AND TOURISMDUPLICATE CLAIM

CVK Hotels & Resorts_Turkey

INCRANSOM📍 TR (TR)📅 December 17, 2025
8
same group

Attack Intelligence

CVK Hotels & Resorts_Turkey was compromised in a ransomware attack attributed to INCRANSOM in December 2025. The organization, operating in the Hospitality and Tourism sector in TR, was added to the group's data leak site as part of an extortion campaign.

INCRANSOM operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

We would like to draw your attention to the fact that even after being notified of the leak, the management of this organization treated it with complete indifference. If you are one of this organization's customers, rest assured that they couldn't care less about your personal data and who will use it and how. ---------------- CVK Hotels & Resorts offers luxury accommodations in the heart of Istanbul, providing guests with a blend of traditional Turkish hospitality and modern comfort. The company operates several hotels, including the CVK Park Bosphorus Hotel, CVK Park Bosphorus Residences, and CVK Taksim Hotel, catering to both leisure and business travelers. Their services include fine dining, spa and fitness facilities, and event spaces, ensuring a comprehensive experience for their clients. With a focus on creating memorable stays, CVK Hotels & Resorts also features a rewards program for guests to earn benefits during their visits.

Additional Details

Other Victims — INCRANSOM (8)

Quick Facts

CountryTR (TR)
SectorHospitality and Tourism
Attack DateDec 17, 2025
Intel Sourceransomware.live
StatusDUPLICATE CLAIM

Threat Group

INCRANSOM
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.