On April 20, 2026, luxury hotel operator Aman became the latest victim in a ShinyHunters “pay or leak” extortion campaign. The attackers claimed to have stolen records on 216,000 customers from the company’s Salesforce CRM system. When Aman did not meet their demands, the group published the data, exposing names, email addresses, phone numbers, physical addresses, dates of birth, genders, nationalities, language preferences, spouse names, and VIP status codes for many of the records.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
Reported Details of the Breach
Public reporting from Have I Been Pwned confirms that the dataset contains over 200,000 unique email addresses. Not every record holds every data field, yet the combination present is unusually rich. Physical addresses, phone numbers, dates of birth, and spouse names appear alongside VIP status markers that identify high-value guests. The breach originated inside Aman’s Salesforce customer relationship management platform, according to the attackers’ own statements. The data was first used as leverage in an extortion demand and then dumped publicly after the deadline passed.
Why This Matters for You and Your Family
When a hotel chain loses contact details, birth dates, home addresses, and family connections, the information becomes raw material for identity thieves, stalkers, and fraudsters. A single exposed phone number or spouse name can unlock further details through public records and social media. For families, the risk extends beyond the primary account holder. Children’s names sometimes appear in family bookings; their dates of birth sit alongside parental addresses. Once this data circulates on underground forums, it can fuel spear-phishing campaigns, account takeover attempts, and even physical security threats at your actual home. The luxury segment offers no protection—attackers deliberately target brands whose customers are perceived to hold higher balances or travel schedules that leave houses empty.
The Doxxing and Identity-Chain Risks
Credential leaks of this nature rarely stop at one company. Emails and phone numbers harvested from Aman can be cross-referenced with gaming accounts, social logins, and family-shared services. A child’s Roblox or Fortnite username linked to a parent’s breached email creates a direct path to doxxing. Attackers map these connections, then escalate from simple spam to targeted extortion or swatting. The presence of spouse names and VIP flags further enriches the profile, allowing criminals to impersonate family members with convincing personal details. Available reporting describes how such identity chains grow rapidly once the first node—here, an Aman reservation record—enters criminal marketplaces.