Ransomware victim disclosure
← All victimsTecnoedil S.A. Constructora
Claimed by Nightspire · listed 3 months ago
Status timeline
- ListedMar 11, 2026
- Data leakeddate unknown
At a glance
- Group
- Nightspire
- Status
- Data leaked
- Country
- Paraguay
- Sector
- Construction
- Listed on leak site
- Mar 11, 2026
About the victim
AI dossier — public-source company profileTecnoedil S.A. Constructora is a Paraguayan construction and public works contracting company registered in Asunción, Paraguay. It operates as a provider of goods and services to the Paraguayan state, participating in public procurement processes regulated by the Dirección Nacional de Contrataciones Públicas. The company has been registered as a state supplier since May 2009, with its legal representative listed as Rolando Gabriel Rios Tomboly.
- Industry
- Construction & Public Works Contracting
- Address
- Avda. Santísimo Sacramento N° 2265 casi Tte. Silverio Molinas, Asunción, Departamento Central, Paraguay
- Founded
- 2009
Attack summary
Severity: medium — Data is listed as published by the group, suggesting some level of exfiltration or disclosure occurred; however, the leak post provides no verifiable details, proof files, or data inventory, and the company is a public-sector contractor whose records could include procurement-sensitive business data. Absent confirmed sensitive data categories or scale, medium is appropriate.The Nightspire ransomware group claims to have attacked Tecnoedil S.A. Constructora, with the disclosure status recorded as data_published; however, the group's leak post contains no details regarding the nature of the attack, data exfiltrated, or proof materials.
What the group claims
Data is not available now.
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

