Ransomware victim disclosure
← All victimsHacienda Zorita Wine Hotel & Spa
listed as haciendazorita.com · Claimed by Threeam · listed 3 years ago
Status timeline
- ListedSep 22, 2023
- Data leakeddate unknown
At a glance
- Group
- Threeam
- Status
- Data leaked
- Country
- Spain
- Sector
- Hospitality
- Listed on leak site
- Sep 22, 2023
About the victim
AI dossier — public-source company profileHacienda Zorita Wine Hotel & Spa is a historic boutique hotel and spa located in Valverdón, Salamanca, Spain. It offers luxury accommodations, farm-to-table gastronomy under the 'Farm Foods' and Slow Food concept, a winery, spa, and event facilities. The property is steeped in history and claims a connection to the Discovery of the Americas.
- Industry
- Boutique Wine Hotel & Spa
- Address
- Ctra. Ledesma, Km. 10, 37115 Valverdón, Salamanca, España
Attack summary
Severity: high — Data has been published by the threat actor, indicating confirmed exfiltration. A hospitality property collects PII including guest details, payment information, and event/corporate client data, representing significant sensitive data exposure under GDPR.The Threeam ransomware group claims to have attacked Hacienda Zorita Wine Hotel & Spa and has published data (disclosed status: data_published), though no specific data volume or ransom demand has been stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Guest personal data
- Reservation records
- Corporate event client data
- Employee records
- Financial/business records
What the group claims
Hacienda Zorita Wine Hotel & Spa, situado en Salamanca, es un icono en de la historia. Podemos decir que fuimos partícipes de uno de los acontecimientos históricos más decisivos: El Descubrimiento de América.
Sources
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

