Ransomware victim disclosure
← All victimsNIXVAL IT Infrastructure
Claimed by Nightspire · listed 3 months ago
Status timeline
- ListedMar 12, 2026
- Data leakeddate unknown
At a glance
- Group
- Nightspire
- Status
- Data leaked
- Country
- Spain
- Sector
- Technology
- Listed on leak site
- Mar 12, 2026
About the victim
AI dossier — public-source company profileNIXVAL IT Infrastructure is the leading data centre infrastructure operator in eastern Spain (Levante region), headquartered in Paterna, Valencia. The company has approximately a decade of experience operating neutral-hosting datacentres offering colocation (racks, cages, dedicated rooms), interconnection, 24×7 support, and cloud connectivity services. Its client base includes major telecommunications operators, IT service integrators, enterprises, and technology start-ups.
- Industry
- Data Centre & Colocation Services
- Address
- Calle Villa de Madrid 44, Polígono Industrial Fuente del Jarro, 46988 Paterna, Spain
Attack summary
Severity: high — NIXVAL is a critical-infrastructure-adjacent data centre and colocation operator serving telecoms, IT integrators, and enterprises. A confirmed data publication by a ransomware group against such an operator carries significant risk of exposure of customer infrastructure data, network configurations, and business-sensitive information, warranting a high severity rating even without detailed data inventory in the post.The Nightspire ransomware group claims to have attacked NIXVAL IT Infrastructure and lists the disclosure status as 'data_published', indicating data exfiltration and/or publication. No further detail on the nature of the data or the extent of the attack is available from the leak post.
What the group claims
Data is not available now.
Sources
- Victim sitewww.nixval.com
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

