Acuna Fombona (AFOM) Listed by spacebears Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Acuna Fombona (AFOM) has been listed by the spacebears ransomware group, with internal files reported exfiltrated. The incident came to light on October 02, 2025; an undisclosed number of individuals may have been affected, and anyone connected to the organisation should verify whether their information was exposed and take appropriate protective steps.
Acuna Fombona (AFOM), a Spanish distributor of surgical products, has been listed by the ransomware group spacebears as a victim of a data-exfiltration attack. The listing was reported on 2 October 2025. Public information remains limited: the number of people affected is unknown, and the group claims that internal files were taken. The incident matters because the company handles sensitive commercial and personal data linked to medical-supply operations across Spain and Portugal.
What is known so far comes chiefly from the group’s own leak-site claim and a brief accompanying description. No independent confirmation of the full scope or method has been published, and the organisation itself has not issued a detailed public statement in the available record.
Inside the incident
According to the reported listing, spacebears claims to have exfiltrated internal files from Acuna Fombona in a ransomware attack. The date of the intrusion itself is undisclosed; only the public listing date of 2 October 2025 is recorded. The number of individuals affected is listed as unknown. The available summary states that the company is a client of Gesimde Asociados S.L. and asserts that “the leak was made possible by this company,” but provides no further technical detail on how access was obtained or whether encryption was also deployed. No ransom demand amount, negotiation timeline, or confirmation of data publication beyond the listing claim has been made public.
Who is spacebears?
Spacebears is a ransomware group that operates in the double-extortion model common among modern cyber-criminal crews: data is stolen first, then systems may be encrypted, and victims are threatened with public release of the material if payment is not made. The group maintains a leak site on which it posts the names of organisations it claims to have compromised, often accompanied by sample files or short descriptions of the data taken. Like other ransomware operators, spacebears typically targets mid-sized enterprises that hold commercially valuable or personally identifiable information. Prior public activity by the group has followed the same pattern of listing victims and asserting possession of internal documents; any specific claims made about Acuna Fombona remain unverified assertions by the group itself.
About Acuna Fombona (AFOM)
Acuña y Fombona (AFOM) is an Asturian company with roughly fifty years of experience distributing surgical products in Spain and Portugal. It supplies international brands used in spinal surgery, traumatology, neurosurgery, thoracic surgery, maxillofacial surgery, ophthalmology, plastic surgery and ENT. Organisations of this type routinely maintain customer and supplier databases, employee records, financial documentation, product catalogues and correspondence with hospitals and clinics. Because the firm sits in the medical-supply chain, a breach can affect not only its own staff and commercial partners but also the broader network of healthcare providers that rely on its products. The company website is publicly listed as acuna-fombona.com.
What was likely exposed
The facts name the following categories as having been claimed by the group:
- Internal files exfiltrated in a ransomware attack
- Database material
- Personal information of employees and clients
- Financial documents
Exact file counts, record volumes and the precise fields contained in those databases are not disclosed. Organisations in the medical-device distribution sector typically hold names, contact details, contractual information, invoices, bank details and employee personnel files; whether any of those specific elements were present in the taken material remains unconfirmed. No evidence of patient clinical records has been stated in the available facts.
The real-world impact
For individuals whose personal data may have been included, the principal risks are identity misuse, targeted phishing and unsolicited contact that appears to come from a trusted medical-supply firm. Employees could face exposure of payroll or personnel details; clients—hospitals, clinics or purchasing departments—could see commercial terms or contact lists circulate. For the organisation itself, the consequences include potential regulatory scrutiny under European data-protection rules, disruption of supplier relationships, and the cost of forensic investigation and notification. Because the number of people affected is unknown and the full contents of the files remain unconfirmed, the precise scale of harm cannot yet be measured. The claim that a third-party service provider facilitated the leak, if accurate, would also raise questions about supply-chain security for other clients of that provider.
Were you affected?
If you are an employee, client or commercial partner of Acuna Fombona, treat any unexpected communication that references the company with caution. Change passwords on accounts that may have been reused, enable multi-factor authentication where available, and monitor financial statements for unusual activity. Keep records of any suspicious emails or calls. Readers can also run a free exposure scan of their email address to check whether their information has already appeared in known breach data sets. Official confirmation from the company or Spanish data-protection authorities should be awaited before drawing final conclusions about personal exposure.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
GC Dental Listed by spacebears Ransomware GroupThe Foot Doctor Listed by spacebears Ransomware GroupThe Foot Doctor's Listed by spacebears Ransomware GroupRios Espinosa Listed by spacebears Ransomware GroupLatest breaches
Publicly posted by spacebears — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.