Ransomware victim disclosure
← All victimsBalneario de Cofrentes
listed as Balneario · Claimed by Qilin · listed 5 months ago
Status timeline
- ListedJan 18, 2026
- Data leakeddate unknown
At a glance
- Group
- Qilin
- Status
- Data leaked
- Country
- Spain
- Sector
- Hospitality and Tourism
- Listed on leak site
- Jan 18, 2026
About the victim
AI dossier — public-source company profileBalneario de Cofrentes is a Spanish health and wellness resort located in Cofrentes, Valencia, Spain, that describes itself as the largest longevity clinic in Europe. The facility combines thermal spa treatments with medical longevity programmes. It operates within the health tourism sector, attracting both domestic and international guests.
- Industry
- Health & Wellness Tourism (Spa & Longevity Clinic)
- Address
- Cofrentes, Valencia, Spain
Attack summary
Severity: high — Data has been published (disclosed status: data_published) by the threat actor. A longevity/health clinic handling guest medical and personal health data means regulated personal and potentially medical data is likely involved, warranting a high severity rating. Insufficient detail to confirm critical-scale regulated data breach.The Qilin ransomware group has listed Balneario de Cofrentes under a data_published disclosure status, indicating that data exfiltration has occurred and stolen data has been published. No specific data categories or ransom amount were stated in the leak post.
Data the group says was taken
AI dossier — extracted from the leak post- Guest/patient personal records
- Medical or health programme data
- Booking and reservation data
- Financial or billing records
What the group claims
N/A
The leak post
captured from the group's siteLaw Firms & Legal Services [John G Yphantides A Professional Law](http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=1e464ce5-6e74-4e62-be0b-eac503e43af8) Law Firms & Legal Services Law Firms & Legal Services [Keller Williams Real Estate - Exton](http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=ac8e3226-6965-4f8e-a2d5-53a0dbce8535)
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

