Ransomware victim disclosure
← All victimsExcel Consultores
Claimed by Qilin · listed 4 hours ago
Status timeline
- ListedJul 30, 2026
- Data leakeddate unknown
At a glance
- Group
- Qilin
- Status
- Data leaked
- Country
- Mexico
- Sector
- Professional Services
- Listed on leak site
- Jul 30, 2026
About the victim
AI dossier — public-source company profileExcel Consultores is a Mexico-based professional services firm specializing in human resources administration, legal counsel, tax planning, auditing, and financial advisory. Operating nationally across Mexico and internationally (US, Central America, Dominican Republic, Spain, Caribbean), the company is headquartered in Lomas de Chapultepec, Mexico City, and has been recognized as a top provider to Mexico's federal government.
- Industry
- Management Consulting & Professional Services (Human Resources, Legal, Tax, Audit)
- Address
- Avenida Prado Norte 305, Lomas de Chapultepec, CDMX, Mexico
Attack summary
Severity: medium — Data has been published by Qilin (disclosed status confirmed), and the victim handles sensitive professional data (tax, legal, HR, financial information) for government and corporate clients. However, without access to the leak post content, proof count, or specific data inventory details, the exact scope and nature of exposure cannot be confirmed. Medium severity reflects confirmed publication by a known group targeting a firm with access to regulated/sensitive client data.The Qilin ransomware group claims to have attacked Excel Consultores and disclosed data; however, the leak post content is marked as unavailable (N/A), so specific claims about encryption, exfiltration scope, or data types cannot be verified from the group's statement.
Data the group says was taken
AI dossier — extracted from the leak post- Client records
- Tax and fiscal planning documents
- Legal files
- HR administration data
- Financial records
What the group claims
N/A
Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

