Ransomware victim disclosure
← All victimsSecond House, S.L.
listed as SECOND HOUSE · Claimed by Incransom · listed 4 hours ago
Status timeline
- ListedSep 21, 2026
- Data leakeddate unknown
At a glance
- Group
- Incransom
- Status
- Data leaked
- Country
- Spain
- Sector
- Hospitality
- Listed on leak site
- Sep 21, 2026
About the victim
AI dossier — public-source company profileSecond House is a privately held real estate company headquartered in Barcelona, Spain, with over 26 years of experience. They specialize in acquiring properties, renovating them, improving rental arrangements, and legalizing building conditions to drive real estate market renewal across Barcelona and surrounding municipalities including L'Hospitalet, Badalona, and Sant Cugat.
- Industry
- Real Estate Development & Property Management
- Address
- Barcelona, Spain
- Founded
- 1998
Attack summary
Severity: low — Disclosure status is 'data_published' but no proof files, data samples, or specific data categories are described in the leak post. No operational impact or data sensitivity details are stated.The incransom group claims to have compromised Second House and published data from the company. No specific details are provided about what data was exfiltrated or whether encryption occurred.
What the group claims
Second House (Second House, S.L.) is a privately held real estate company headquartered in Barcelona, Spain, with over 26 years of experience in the property sector. Their business model centers on buying properties and adding value to them — through renovation works, improving rental situations, and legalizing the existing state of buildings — effectively driving renewal of the real estate market in Barcelona and its surroundings. They are actively acquiring in the Barcelona area (including L'Hospitalet, Badalona, Sant Cugat, etc.)
Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

