Ransomware victim disclosure
← All victimsAltius Geotecnia y Obras Especiales
Claimed by Qilin · listed 5 months ago
Status timeline
- ListedJan 20, 2026
- Data leakeddate unknown
At a glance
- Group
- Qilin
- Status
- Data leaked
- Country
- Spain
- Sector
- Construction
- Listed on leak site
- Jan 20, 2026
About the victim
AI dossier — public-source company profileAltius Geotecnia y Obras Especiales is a Spanish company with over 20 years of experience specialising in geotechnical solutions and civil/public works construction. Their services include dam and reservoir works, slope stabilisation, ground improvement, special foundations, structural repair, and monitoring. They serve both public and private sector clients across transport and hydraulic infrastructure projects.
- Industry
- Geotechnical Engineering & Specialist Civil Works
Attack summary
Severity: high — Data has been published (data_published status confirmed), indicating confirmed exfiltration and release of company data. The company works on public infrastructure projects (transport, hydraulic, dams), meaning leaked data could include sensitive engineering, contractual, or project documentation. Absence of stated data size or inventory limits escalation to critical.The Qilin ransomware group has listed Altius Geotecnia y Obras Especiales as a victim with a disclosed status of data_published, indicating that data has been exfiltrated and published. No ransom amount or specific data volume was stated in the post.
What the group claims
N/A
The leak post
captured from the group's siteLaw Firms & Legal Services [John G Yphantides A Professional Law](http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=1e464ce5-6e74-4e62-be0b-eac503e43af8) Law Firms & Legal Services Law Firms & Legal Services [Keller Williams Real Estate - Exton](http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=ac8e3226-6965-4f8e-a2d5-53a0dbce8535)
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

