Ransomware victim disclosure
← All victimsColegio Oficial de Arquitectos de León (COAL)
listed as The Official Collegeof Architects of León (COAL) · Claimed by Akira · listed 3 hours ago
Status timeline
- ListedOct 3, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- Mexico
- Sector
- Professional Services
- Listed on leak site
- Oct 3, 2026
About the victim
AI dossier — public-source company profileThe Official College of Architects of León (COAL) is a professional regulatory body established in 1931 serving architects in León, Spain, and historically the regions of Asturias and Galicia until the Galician college separated in 1973 and the Asturian college in 1981.
- Industry
- Professional Services & Architecture
- Address
- León, Spain (with historical coverage of Asturias and Galicia regions)
- Founded
- 1931
Attack summary
Severity: critical — Confirmed exfiltration and public publication of 77 GB of data including personal documents (passports), financial records, and PII at scale affecting an unknown number of individuals (students, clients, members).Akira claims to have exfiltrated 77 GB of corporate data including detailed personal information (passports), financial records, and student/client information. The group has published access to the data and advertises password-free archives available for download.
Data the group says was taken
AI dossier — extracted from the leak post- Passport copies
- Personal identification documents
- Financial records
- Student information
- Client information
- Corporate data
What the group claims
The Official College of Architects of León (COAL) was established on July 12, 1931, encompassi ng the regions of León, Asturias, and Galicia. The College of Galicia was legally separated in 1973 and the College of Asturias in 1981. Here is the access to 77gb of corporate data. Detailed personal information (passports), finan cials, students and clients information and so on. Click the download button. You will find several password-free archives. Click on any of them to start the download.
Source
Indexed 3 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

