Ransomware victim disclosure
← All victimsGrupo Ronda y Auditores S.L.P.
listed as GRUPO RONDA · Claimed by lamashtu · listed 1 month ago
Status timeline
- Listed
Apr 14, 2026
- Data leaked
At a glance
- Group
- lamashtu
- Status
- Data leaked
- Country
- MX
- Sector
- Business Services
- Listed on leak site
- Apr 14, 2026
About the victim
AI dossier — public-source company profileGrupo Ronda y Auditores S.L.P. is a Spanish professional services firm operating since 1978, providing statutory and voluntary audits, insolvency administration, forensic accounting reports for judicial proceedings, business advisory, and vehicle registration management (gestoría). The firm is staffed by registered auditors, insolvency administrators, forensic accountants, lawyers, and business administration graduates, and serves clients throughout Spain.
- Industry
- Audit, Forensic Accounting & Business Advisory Services
- Founded
- 1978
Attack summary
Severity: high — Data has been confirmed published by the threat actor. As an audit and forensic accounting firm, Grupo Ronda handles highly sensitive client financial, legal, and judicial records, including PII and confidential business data, making exposure of significant consequence even without explicit volume figures.The Lamashtu ransomware group claims to have attacked Grupo Ronda and has published data (disclosed status: data_published), though the leak post does not specify whether encryption, exfiltration, or both occurred, nor does it detail the volume or nature of the stolen data.
Data the group says was taken
AI dossier — extracted from the leak post- Client financial and accounting records
- Forensic accounting reports
- Judicial proceeding documents
- Business advisory files
- Corporate legal documentation
- Employee/professional credentials data
What the group claims
Grupo Ronda Auditores es un despacho constituido por un equipo de: Auditores, Mediadores Concursales, Expertos Contables, Licenciados en Derecho, debidamente colegiados. Licenciados en Administración y Dirección de empresas
Sources
Source
Indexed 1 month agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
