Ransomware victim disclosure
← All victimsCiberviaxes Especial
listed as ciberviaxesespecial.net · Claimed by Lockbit3 · listed 2 years ago
Status timeline
- ListedJul 31, 2024
- Data leakeddate unknown
At a glance
- Group
- Lockbit3
- Status
- Data leaked
- Country
- Spain
- Sector
- Technology
- Listed on leak site
- Jul 31, 2024
About the victim
AI dossier — public-source company profileCiberviaxes Especial is a Spanish travel agency based in A Coruña that specializes in curated travel packages. They offer organized trips to destinations including Croatia, Tuscany, Provence, and domestic Spanish locations, marketed in partnership with ABANCA (a Spanish bank). The company holds travel authorization number XG-402.
- Industry
- Travel & Tourism
- Address
- Calle Federico Tapia, 41, 15005 A Coruña, Spain
Attack summary
Severity: medium — Confirmed data exfiltration with published evidence (email addresses and internal website data), but no indication of large-scale PII exposure, financial data, or operational disruption. Travel agency data is moderately sensitive but not classified as regulated sensitive data.LockBit3 claims to have compromised Ciberviaxes Especial and exfiltrated data. The leak post contains what appears to be email addresses and website content, suggesting data exfiltration occurred.
Data the group says was taken
AI dossier — extracted from the leak post- email addresses
- website content
- customer/contact information
What the group claims
981216600 [email protected] Ciberviaxes especial Viajes para ti ABANCA Espacio +60 Afundación Toscana ¡Clica y conoce las características de este fantástico viaje! Croacia ¡Clica y conoce las características de este fantástico viaje! País Vasco ¡C...
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

