Grupo DIRIA Listed by dragonforce Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Grupo DIRIA has been listed by the dragonforce ransomware group after internal files were exfiltrated in a ransomware attack. The listing was reported on 27 August 2025, and affected individuals should review any notifications from the organisation and follow recommended security steps if their data is involved.
Grupo DIRIA, a luxury hospitality provider operating hotels and resorts in Tamarindo Beach, Costa Rica, has been listed by the ransomware group dragonforce as of a report dated August 27, 2025. Public details indicate that internal files were exfiltrated in a ransomware attack, though the number of people affected remains unknown and further specifics about the incident have not been disclosed.
This listing matters because organisations in tourism and hospitality routinely handle guest records, operational data and related internal material. When such material is claimed to have been taken, those connected to the company face potential risks that warrant careful attention even while many facts stay unconfirmed.
What happened
According to the available record, Grupo DIRIA was listed by the dragonforce ransomware group on or around August 27, 2025. The report states that internal files were exfiltrated during a ransomware attack. No public confirmation of the precise timing of the intrusion, the scale of systems affected, the method of initial access, or any ransom demand has been provided. The number of individuals whose data may be involved is listed as unknown. The listing itself constitutes a claim by the group rather than an independently verified disclosure from the organisation.
The group behind it: dragonforce
Dragonforce is a ransomware operation that has appeared in public reporting as a group that conducts double-extortion style attacks: encrypting systems while also claiming to steal data and threatening to publish it on leak sites if demands are not met. Like other groups in this category, it typically advertises victims on dedicated leak portals to increase pressure. Public knowledge of the group centres on its use of ransomware tooling and data-exfiltration claims rather than on any single confirmed technical signature unique to every incident.
In this case, dragonforce has listed Grupo DIRIA and claims that internal files were taken. No additional statements attributed specifically to the group about this victim—such as sample file counts, screenshots, or deadlines—appear in the provided facts. The listing should therefore be treated as an unverified claim pending further confirmation or independent evidence.
About Grupo DIRIA
Grupo DIRIA operates in the tourism and hospitality sector, providing luxury accommodation through hotels and resorts in the Tamarindo Beach area of Costa Rica. Public descriptions of the company emphasise high-quality lodging, respect for local cultural traditions, modern comfort and security for guests, and an overall focus on delivering an authentic Costa Rican experience to travellers seeking immersive stays.
Companies of this type typically maintain guest reservation systems, payment records, staff information, supplier contracts and internal operational documents. A ransomware incident affecting such an organisation is consequential because the hospitality industry relies on trust and the continuous handling of personal and commercial data; any disruption or exposure can affect both guests and the business’s ability to operate normally.
The information in question
The facts state that internal files were exfiltrated in the ransomware attack. No further breakdown of the exact data types—such as guest names, contact details, payment card information, employee records or financial documents—has been disclosed. The precise contents therefore remain unconfirmed.
Organisations in luxury hospitality commonly hold reservation databases, guest profiles, billing information, staff personnel files and various internal operational documents. While these categories represent what is typically present, it cannot be stated as fact that any specific category was among the material claimed by dragonforce. Public detail on the actual files is limited to the general description of “internal files.”
The real-world impact
For individuals whose information may have been among the exfiltrated files, the primary risks include potential misuse of personal details for phishing, social-engineering attempts or identity-related fraud. Guests or staff could receive unsolicited communications that appear to come from the company or related services. Because the number of people affected is unknown and the exact data types are unconfirmed, the concrete scope of these risks cannot yet be measured.
For Grupo DIRIA itself, a ransomware incident can interrupt booking systems, guest services and internal operations, and may require costly recovery, forensic investigation and notification efforts. Reputational effects are also possible when a hospitality brand is publicly listed by a ransomware group. These outcomes remain contingent on the still-undisclosed details of what was taken and how systems were affected.
What to do if you're exposed
If you have stayed at a Grupo DIRIA property, worked with the company, or otherwise shared personal information with it, treat the situation cautiously. Monitor bank and credit-card statements for unfamiliar activity, enable multi-factor authentication on email and financial accounts, and be alert to phishing messages that reference recent travel or hospitality services. Consider placing a fraud alert with credit-reporting agencies if you believe sensitive identifiers may be involved. Change passwords that you may have reused across services.
Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. This step provides an additional, practical way to assess whether personal contact information has surfaced elsewhere, independent of the still-limited public details of this particular incident.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Immling Festival DER Festspielort im Chiemgau Listed by dragonforce Ransomware GroupGrupo Serex Listed by dragonforce Ransomware GroupAllgäu Stern Hotel Listed by dragonforce Ransomware GroupPark Country Club Listed by dragonforce Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Grupo DIRIA Listed by dragonforce Ransomware Group →
Publicly posted by dragonforce — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.