Ransomware victim disclosure
← All victimsRLC Transportes
listed as rlc.es · Claimed by Safepay · listed 5 months ago
Status timeline
- ListedJan 23, 2026
- Data leakeddate unknown
At a glance
- Group
- Safepay
- Status
- Data leaked
- Country
- Spain
- Sector
- Technology
- Listed on leak site
- Jan 23, 2026
About the victim
AI dossier — public-source company profileRLC Transportes is a Spanish international freight transport and logistics company headquartered in Valencia, Spain, with over 30 years of experience. The company operates a fleet of 300 owned trucks plus more than 180 dedicated vehicles, staffed by over 100 professionals across 7 branches. It specialises in import/export cargo, partial loads, intermodal transport, and temperature-controlled logistics for food and pharmaceutical products, and has been recognised as the leading import-capacity transport company in Spain by the specialist publication Transporte XXI.
- Industry
- International Freight Transport & Logistics
- Address
- Valencia, Spain
- Employees
- 100+
Attack summary
Severity: high — Data has been published by the threat actor. RLC handles sensitive logistics data for pharmaceutical and food-grade supply chains (certified under IFS Logistics, QS, and EU Good Distribution Practice for human medicines), meaning exfiltrated data likely includes regulated supply-chain and client business records at meaningful scale.SafePay ransomware group claims an attack on RLC Transportes and has published data (disclosed status: data_published), though the leak post does not specify the volume of data exfiltrated or whether encryption was also carried out.
Data the group says was taken
AI dossier — extracted from the leak post- Company operational data
- Client transport records
- Logistics and supply chain data
- Potentially pharmaceutical distribution records
- Potentially food-chain traceability records
What the group claims
RLC Transportes (operating under Rau Load Cargo, S.L.) is a Spanish logistics and freight-transport company based in El Puig de …
The leak post
captured from the group's site# SafePay ransomware has never provided and does not provide the RaaS JMIGE appears to be a company with limited publicly available information, making precise classification difficult. Based on naming conventions and … Is a U.S.-based freight transportation company operating primarily in interstate logistics. The company specializes in hauling general freight, agricultural products … Is a private healthcare organization based in Catalonia, Spain, operating in the Hospitals & Physicians Clinics sector. Founded in 1993 … Is an Italian food manufacturing company specializing in frozen gastronomic products. Founded in 1935 in Francavilla Fontana, the company has … Global Merchandising Services (GMS) is an international entertainment merchandising company founded in 2008. It specializes in developing and managing merchandise … Is an Italian firm that likely operates in the field of professional services such as architecture, design, or engineering consulting. … Appears to be a Belgian-based entity likely involved in professional training, technology consulting, or industrial services. While detailed public data … Is a German industrial company specializing in metal processing an…
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

