Ransomware victim disclosure
← All victimsAlter Consultores Legales
Claimed by Qilin · listed 2 days ago
Status timeline
- ListedAug 28, 2026
- Data leakeddate unknown
At a glance
- Group
- Qilin
- Status
- Data leaked
- Country
- Spain
- Sector
- Professional Services
- Listed on leak site
- Aug 28, 2026
About the victim
AI dossier — public-source company profileAlter Consultores Legales is a Madrid-based law and professional services firm offering legal advice across multiple practice areas (civil, commercial, labor, administrative, tax, etc.), compliance programs, accounting services, and HR management solutions. They provide both legal consultation and specialized accounting/fiscal management services to corporate clients.
- Industry
- Legal & Professional Services
- Address
- Paseo de Recoletos 3, 1ª planta, 28004, Madrid, Spain
Attack summary
Severity: medium — Law firm data typically includes sensitive client information and privileged communications; however, without confirmation of exfiltration or operational impact in the provided leak post, and given the disclosed_status of 'data_published' without detail, confidence in exact scope is limited. Classified as medium due to the professional services/legal sector handling regulated data.The qilin group claims to have attacked Alter Consultores Legales. No leak post content was provided; disclosed status indicates data has been published, but specific details on encryption, exfiltration, or data types are not available in the submitted materials.
Data the group says was taken
AI dossier — extracted from the leak post- client legal files
- accounting records
- employment/HR data
- compliance documentation
What the group claims
N/A
Sources
Source
Indexed 2 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

