Ransomware victim disclosure
← All victimsCPQ-EKIUM
listed as CPQ Ingenieros · Claimed by Thegentlemen · listed 4 months ago
Status timeline
- ListedFeb 6, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Country
- Spain
- Listed on leak site
- Feb 6, 2026
About the victim
AI dossier — public-source company profileCPQ Ingenieros, now rebranded as CPQ-EKIUM following a 2023 merger with French engineering group EKIUM, is a Spanish engineering firm specialising in the design and construction of industrial process plants. Their sectors include chemical, pharmaceutical, cosmetics, and food industries, with clients such as Henkel, AkzoNobel, and NALCO. The company operates multiple offices and has completed numerous significant industrial projects.
- Industry
- Industrial Process Plant Engineering
Attack summary
Severity: medium — Data is listed as published, indicating likely exfiltration, but no specifics on data type, volume, or regulated/sensitive content are available from the truncated leak post. The victim is an engineering firm handling confidential industrial project data, which is significant but not confirmed to include large-scale PII or regulated data.The ransomware group 'thegentlemen' claims an attack against CPQ Ingenieros with the disclosure status listed as 'data_published', suggesting data exfiltration has occurred; however, the leak post content was obstructed by a bot-verification page and no specific data types or volumes were detailed.
What the group claims
cpqingenieros.com zoominfo.com/c/cpq-ingenieros/404026171 specializes in the design of process plants across various sectors including chemical, pharmaceutical, biotechnological, food, and cosmetic industries. Their services encompass basic processes, detailed engineering, project management, construction supervision, startup assistance, and legal compliance. The company caters to large and medium-sized enterprises committed to quality and transparency.
The leak post
captured from the group's siteGentlecloud Protection 🛡️ Gentlecloud Verifying your browser... Initializing security checks... I'm not a bot
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

