Ransomware victim disclosure
← All victimsEmpty
Claimed by thegentlemen · listed 5 hours ago
Status timeline
- Listed
Jun 8, 2026
- Data leaked
At a glance
- Group
- thegentlemen
- Status
- Data leaked
- Country
- ES
- Sector
- Not Found
- Listed on leak site
- Jun 8, 2026
About the victim
AI dossier — public-source company profileEmpty is a Spanish architecture and construction firm headquartered in Madrid, specializing in complex architectural projects, museums, and exhibitions. With over 50 professionals across offices in Madrid, Barcelona, and Paris, the company delivers high-profile builds including the Spanish Pavilion at Expo Dubai 2020 and BBVA's 'La Vela' headquarters.
- Industry
- Architecture & Construction
- Address
- Madrid, Spain (headquarters); offices in Barcelona and Paris
- Employees
- 50+
Attack summary
Severity: low — Post contains only a listing/announcement with no proof files, screenshots, or specific data inventory disclosed. No ransom demand stated. Insufficient evidence of actual compromise or data publication.The threat actor claims data exfiltration from Empty but provides no details on specific data types, encryption status, or ransom demands in the disclosed post.
What the group claims
***.es zoominfo.com/c/empty/439336503 Empty is a prominent Spanish construction and architecture firm headquartered in Madrid, specializing in the execution of complex architectural, museum, and exhibition projects. With a team of over 50 professionals and offices in Madrid, Barcelona, and Paris, the company excels in mobilizing technical resources to deliver high-profile builds, such as the Spanish Pavilion at Expo Dubai 2020 and BBVA’s "La Vela" headquarters. Founded with the vision of redefining the construction industry, Empty acts as a comprehensive partner for drafting and executing large-scale, sophisticated structures
Sources
- Victim siteempty.es
Source
Indexed 5 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
