Ransomware victim disclosure
← All victimsACI Proyectos SAS
Claimed by Qilin · listed 5 hours ago
Status timeline
- ListedOct 10, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileACI Proyectos SAS is a Colombian-based project management and consulting firm operating across Latin America (Colombia, Peru, Chile). They provide supervisory, technical, administrative, legal, financial, and environmental services to infrastructure, oil & gas, energy, mining, and construction projects. The company operates with integrated management systems and sustainability standards.
- Industry
- Engineering & Project Management Consulting - Infrastructure, Oil & Gas, Energy
- Address
- Carrera 7 No 156 - 10, Piso 31, Torre Krystal, Bogotá, Colombia (primary); Additional offices in Lima, Peru and Santiago, Chile
Attack summary
Severity: medium — Data has been published by the group (disclosed status confirmed), indicating confirmed exfiltration. However, the leak post itself is marked as 'N/A' or truncated, and no specific data inventory, proof files, or sensitive data categories are documented in the available materials. The company handles infrastructure and energy sector projects which may involve commercially sensitive information, but the absence of proof details or confirmed PII/regulated data exposure prevents a 'high' classificaThe Qilin group claims to have breached ACI Proyectos SAS and published data. No specific details about the nature of the breach (encryption vs. exfiltration), data categories, or ransom demand are provided in the available leak post excerpt.
What the group claims
N/A
Sources
Source
Indexed 5 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

