Ransomware victim disclosure
← All victimsCentro de Desarrollo Emprendedor Ensenada
Claimed by Qilin · listed 5 months ago
Status timeline
- ListedJan 21, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileCentro de Desarrollo Emprendedor Ensenada (CDEE) appears to be a government-affiliated entrepreneurship development center based in Ensenada, Baja California, Mexico, operating under or associated with the Baja California state government (bajacalifornia.gob.mx). It likely provides support services, training, and resources to small businesses and entrepreneurs in the Ensenada region. No public site content was available to confirm further operational details.
- Industry
- Government – Entrepreneurship & Business Development
Attack summary
Severity: medium — Data has been published (disclosed status confirms exfiltration), but no specifics on data type, volume, or confirmed presence of regulated/sensitive PII are available from the post; the government-affiliated nature raises concern but insufficient evidence exists to classify as critical.The Qilin ransomware group has listed Centro de Desarrollo Emprendedor Ensenada with a 'data_published' status, indicating that data claimed to have been exfiltrated from the organization has been published. The leak post provides no specific details about the volume or nature of the data disclosed.
What the group claims
N/A
The leak post
captured from the group's siteLaw Firms & Legal Services [John G Yphantides A Professional Law](http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=1e464ce5-6e74-4e62-be0b-eac503e43af8) Law Firms & Legal Services Law Firms & Legal Services [Keller Williams Real Estate - Exton](http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=ac8e3226-6965-4f8e-a2d5-53a0dbce8535)
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

