Aman Data Breach (2026): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Aman disclosed a data breach on April 20, 2026, affecting 216,000 individuals whose names, email addresses, dates of birth, genders, and language preferences were exposed. Check whether your information was included and consider changing passwords or enabling additional account protections if it was.
Inside the incident
The incident was first publicly referenced on April 20, 2026. Handala listed Aman on its leak site as part of a claimed “pay or leak” extortion campaign and stated that the data had been taken from the company’s Salesforce CRM. The material was subsequently posted publicly. The listing indicated more than 200,000 unique email addresses were present. No confirmed information has been released about the initial access method, the timeline of the intrusion, or the full volume of files involved.
Inside handala
Handala is a publicly documented threat actor that has conducted multiple data-extortion operations. The group’s typical pattern involves claiming access to an organization’s systems, listing the victim on a dedicated leak site, and threatening or carrying out public release of data when payment demands are not met. Prior activity attributed to the group in open sources has followed the same extortion and disclosure sequence against other targets.
Aman and its sector
Aman is an ultra-luxury hotel brand whose operations require detailed customer records to manage high-end travel, accommodation, and concierge services. Hospitality companies of this type routinely store contact information, identity details, and service preferences in customer-relationship-management platforms to support bookings and personalized offerings.
What was likely exposed
The data types named in connection with the incident are dates of birth, email addresses, genders, language preferences, names, nationalities, phone numbers, and physical addresses. Some records also referenced spouse names and VIP status codes. The precise contents of every record remain unconfirmed beyond the reported categories.
- Dates of birth
- Email addresses
- Genders
- Language preferences
- Names
- Nationalities
- Phone numbers
- Physical addresses
The real-world impact
Individuals whose information appeared in the dataset may receive unsolicited messages or be targeted in phishing attempts that reference the exposed details. Organizations holding similar customer records face ongoing operational and reputational consequences when such data leaves their control, regardless of the initial cause of the exposure.
Were you affected?
Anyone who has stayed at an Aman property or provided contact details to the brand can review account activity for unexpected changes and enable additional authentication where available. Readers can run a free exposure scan of their email to check whether their information has surfaced in known breach data.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Kash Patel current director of the FBI Listed by handala Ransomware GroupShock for Israeli Intelligence: 100,000 Classified Emails of Mossad’s Ex-Deputy Director S... Listed by handala Ransomware GroupUnprecedented Disclosure of 50 Senior Israeli Air Force Officers’ Information Listed by handala Ransomware GroupFull Access: Jerusalem’s Security Cameras in Handala’s Hands Listed by handala Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Aman Data Breach (2026) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.