Ransomware victim disclosure
← All victimsAvant Grup
Claimed by Snatch · listed 3 years ago
Status timeline
- ListedJun 5, 2023
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileAvant Grup is a Spanish passenger transport company based in Barcelona with over 50 years of experience providing coach and mobility services. The company operates across multiple cities in Spain, serving tourism, congresses, cruise port operations (Barcelona, Tarragona, Palamós), school transport, private transfers, and adapted transport. It holds ISO certifications and Biosphere/Responsible Tourism commitments.
- Industry
- Passenger Coach & Mobility Services
- Address
- Barcelona, Spain (with operational bases across Spain; phone: +34 93 652 84 88)
Attack summary
Severity: high — Data has been published by the threat actor, confirming exfiltration. The company handles passenger transport including school transport and cruise operations, and likely holds PII for clients, employees, and suppliers. Published data elevates this beyond medium despite no explicit volume figure.The Snatch ransomware group claims to have attacked Avant Grup and has published data (disclosed status: data_published), indicating exfiltration of company data; no ransom amount or specific data volume has been stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Operational/logistics data
- Client reservation records
- Corporate documents
- Employee/HR data (inferred)
- Supplier information (inferred from 'Área Proveedor')
What the group claims
Avant Grup, has a wide network of operational bases distributed in different cities in order to cover the demand in mobility services that be generated. This extensive offer of service coverage provides our clients with a global solution throughout the national territory. Our centralized reservation
Sources
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

