Ransomware victim disclosure
← All victimsAUTOCARES CARRETERO
Claimed by Nightspire · listed 5 months ago
Status timeline
- ListedJan 14, 2026
- Data leakeddate unknown
At a glance
- Group
- Nightspire
- Status
- Data leaked
- Country
- Spain
- Sector
- Transportation/Logistics
- Listed on leak site
- Jan 14, 2026
About the victim
AI dossier — public-source company profileAutocares Carretero is a Spanish transportation company operating under the domain autocarescarretero.com. Based in Spain, the company appears to provide coach and bus transport services, as indicated by the term 'autocares' (the Spanish word for coaches/motor coaches). No further operational details could be confirmed due to unavailability of public site content.
- Industry
- Passenger Road Transport (Coach & Bus Services)
Attack summary
Severity: medium — Data is marked as published, confirming some level of exfiltration, but no details on data type, volume, or sensitivity are available from the post. The victim is a transport operator with no indication of regulated or critical-infrastructure-scale data exposure, warranting medium rather than high severity.The Nightspire ransomware group claims an attack on Autocares Carretero and has listed the victim under a 'data_published' status, indicating exfiltrated data has been released. The leak post provides minimal detail beyond the company name, with no ransom amount or data volume specified.
What the group claims
AUTOCARES CARRETERO
Sources
- Victim siteautocarescarretero.com
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

