CARTONAJES BERNABEU SAU www.cartonajesbernabeu.com serviced by IT company Verne Group www.... Listed by blacknevas Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
CARTONAJES BERNABEU SAU, whose website is www.cartonajesbernabeu.com, was listed by the BlackNevas ransomware group on September 09, 2025, after internal files were exfiltrated from systems hosted by Verne Group. Individuals should check whether any of their data was exposed and take steps to protect themselves.
CARTONAJES BERNABEU SAU, a Spanish packaging manufacturer based in Manises, Valencia, has been listed by the blacknevas ransomware group as a victim of a data breach involving the exfiltration of internal files. The incident was reported on 9 September 2025. Public detail remains limited: the number of people affected is unknown, and no independent confirmation of the group's claims has been released. The company is described as being serviced by the IT firm Verne Group for cybersecurity and monitoring. What is known so far is that blacknevas claims to have taken internal files during a ransomware attack and has posted a file list offering access upon request, with a claimed volume of 1.2 TB.
For a firm that produces cardboard containers and packaging for multiple industries, any exposure of internal material raises practical questions about operational continuity, supplier and customer relationships, and the security of business data. The listing itself is a claim by the group rather than verified proof of full compromise.
Breaking down the breach
According to the available record, CARTONAJES BERNABEU SAU appears on a blacknevas leak-site listing. The group states that internal files were exfiltrated in a ransomware attack and that a list of those files is available, with any file provided on request via a shared link. The claimed data volume is given as 1.2 TB. The report notes that the company is serviced by Verne Group, an IT provider focused on cybersecurity and monitoring. No further technical details—such as the initial access method, the precise date of intrusion, encryption of systems, or ransom demands—have been disclosed in the public facts. The number of individuals whose data may be involved is listed as unknown. Timing beyond the 9 September 2025 reporting date is not provided. All specifics about the scale and contents therefore rest on the group's unverified assertions.
Inside blacknevas
Blacknevas is a ransomware operation that has appeared in public reporting as a group that encrypts victim systems and exfiltrates data before threatening to publish it. Like many contemporary ransomware actors, it typically maintains a leak site where it names organisations, posts sample file lists or data volumes, and offers further material on request as pressure to pay. Public accounts of the group describe double-extortion tactics: locking systems while simultaneously stealing files so that non-payment risks both operational disruption and public exposure. Prior activity attributed to blacknevas and similar groups has targeted mid-sized industrial and manufacturing firms across Europe and elsewhere, often through common initial vectors such as compromised credentials or unpatched remote services, though no such method is confirmed for this particular case. The listing of CARTONAJES BERNABEU SAU should be read as the group's claim; independent verification of the files or the 1.2 TB figure has not been supplied in the available record.
CARTONAJES BERNABEU SAU and its sector
CARTONAJES BERNABEU SAU specialises in the production and sale of cardboard containers and packaging. Founded in 1965 and headquartered in Manises, Valencia, Spain, it forms part of the wider Cartonajes Bernabeu group and maintains production and warehouse facilities. The company supplies customised packaging solutions to various industries. Packaging manufacturers of this type sit in the middle of supply chains: they hold design specifications, order histories, logistics data, supplier contracts and customer lists, and they often process commercial and sometimes personal information related to employees, drivers and business contacts. Because packaging is essential to food, consumer goods, pharmaceuticals and industrial products, disruption or data exposure at such a firm can affect multiple downstream partners. The involvement of an external IT and cybersecurity provider, Verne Group, is noted in the facts, but no assessment of that relationship's role in the incident is available.
What data was at risk
The facts state only that internal files were exfiltrated in a ransomware attack. No inventory of specific data categories—such as employee records, customer databases, financial documents or intellectual property—has been confirmed. Organisations in the cardboard packaging sector typically retain production schedules, quality-control records, commercial contracts, shipping details, and internal administrative files that may include personal data of staff and business contacts. Because the exact contents remain unconfirmed, it is not possible to state which of these categories, if any, were among the claimed 1.2 TB. The group's offer to supply files from a published list is itself an unverified claim.
What's at stake
For individuals whose information may have been among the internal files, the concrete risks include potential misuse of contact details, identity-related fraud if personal identifiers were present, or targeted phishing that leverages knowledge of the company's operations. For the organisation, the stakes centre on operational continuity, possible regulatory notification duties under Spanish and EU data-protection rules, reputational impact with customers who rely on secure packaging supply, and the cost of investigation and recovery. Because the number of people affected is unknown and the precise data types are undisclosed, the full extent of these risks cannot yet be quantified. The listing alone does not establish that every claimed file has been widely distributed.
Were you affected?
If you are a current or former employee, supplier or customer of CARTONAJES BERNABEU SAU, treat any unexpected contact that references the company with caution. Monitor financial and email accounts for unusual activity, enable multi-factor authentication where available, and consider changing passwords used for related services. Organisations of this kind sometimes hold limited personal data; if you receive formal notification from the company or Spanish authorities, follow the guidance provided. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach datasets elsewhere. Public detail on this incident remains limited, so further official statements from the company or regulators will be the most reliable source of updates.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Undefasa Listed by blacknevas Ransomware GroupCash and carry - COSAEN GRUP Listed by blacknevas Ransomware GroupThe company MST (Sanko Makina and ASKO Holding) Listed by blacknevas Ransomware GroupParamount Health Services & Insurance TPA Pvt. Ltd Listed by blacknevas Ransomware GroupLatest breaches
Publicly posted by blacknevas — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.