Ransomware victim disclosure
← All victimsInstapack
listed as instapack.es · Claimed by lockbit5 · listed 22 days ago
Status timeline
- Listed
Apr 29, 2026
- Data leaked
At a glance
- Group
- lockbit5
- Status
- Data leaked
- Country
- ES
- Sector
- Business Services
- Listed on leak site
- Apr 29, 2026
About the victim
AI dossier — public-source company profileInstapack is a Spanish professional courier and immediate delivery service with over 30 years of experience in the sector. The company operates across more than 30 cities throughout Spain with a fleet of approximately 1,000 delivery riders and proprietary tracking software integrated with its local agencies. It offers services including same-hour pickup and delivery (Instapack Now) and real-time shipment tracking.
- Industry
- Courier & Immediate Delivery Services
- Address
- Spain (operates in more than 30 cities across Spain; no specific street address stated)
Attack summary
Severity: high — Data has been confirmed as published by the ransomware group. As a courier service handling customer shipment records at scale across 30+ Spanish cities with 1,000 delivery personnel, the exfiltrated data likely contains significant personal and business data (customer PII, delivery addresses, commercial records), warranting a high severity classification.The LockBit 5 group claims to have attacked Instapack and has published data (disclosed status: data_published), indicating exfiltration of company data; no specific ransom amount or data volume was stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Company operational data
- Customer shipment records
- Potentially proprietary logistics software data
What the group claims
Instapack is a professional courier service with over 30 years of experience, offering immediate del...
Sources
Source
Indexed 22 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
