LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surface
Recent BreachesData breach tracker

Recent Breaches › Diater Listed by Deadlock Ransomware Group

HIGH severity claimedUnverified claimHow we verify

Diater Listed by Deadlock Ransomware Group: What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·July 28, 2026
Diater Listed by Deadlock Ransomware Group

Reported July 28, 2026.

HIGH
Severity
1
Data types exposed
July 28, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Diater was listed by the Deadlock ransomware group on 28 July 2026, with internal files reported to have been exfiltrated. Individuals connected to Diater should review any notices from the organisation and take appropriate protective steps.

Severity & verification
HIGH severity claimedUnverified claim
Exposes medical data.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Was your email in the Diater Listed by Deadlock Ransomware Group breach?
See every leak tied to your email — not just this one. 15-second check, no card, no account.

People connected to Diater — employees, research partners, clinicians, or patients whose details may sit in company systems — face a familiar and unsettling question: whether internal files taken in a claimed ransomware attack could expose information that affects their privacy, finances, or care. Public reporting so far is limited, and the number of people involved has not been stated.

On 28 July 2026, the Spanish biopharmaceutical firm Diater was listed by the ransomware group Deadlock. The listing asserts that internal files were exfiltrated. What follows sets out what is known, what remains unconfirmed, and what practical steps matter for anyone who may be touched by the incident.

Inside the incident

According to public breach reporting dated 28 July 2026, Diater — formally Laboratorio de Diagnóstico y Aplicaciones Terapéuticas, SA — was named on a Deadlock-associated leak site. The available summary states that internal files were exfiltrated in a ransomware attack. No confirmed figure for people affected has been published. Timing of the intrusion, the initial access method, encryption details, ransom demands, and whether any data has been released beyond the listing itself are not disclosed in the material provided.

At this stage the incident rests on the group’s claim and the secondary reporting of that claim. Independent confirmation of the full scope, the exact systems involved, or successful recovery of any stolen material has not been set out in the facts at hand. Organisations in this position typically investigate, contain systems, and notify regulators and affected parties under applicable law; those steps, if taken, are not detailed here.

The group behind it: Deadlock

Deadlock is a ransomware operation known in public reporting for double-extortion tactics: encrypting victim environments while also copying data and threatening to publish or sell it if payment is not made. Like other groups in this category, it has used dedicated leak sites to name organisations and, in some cases, to stage sample files or full dumps as pressure. Affiliates or operators commonly gain entry through phishing, exposed remote services, or stolen credentials, then move laterally before deploying ransomware and exfiltration tools.

Public documentation of Deadlock’s broader campaign history exists outside this case; none of that background should be read as verified detail about Diater specifically. Regarding this victim, the group claims a listing tied to exfiltrated internal files. That claim has not been independently validated in the facts supplied, and no quotes, file counts, or ransom figures from Deadlock about Diater are available here.

Diater and its sector

Diater is a Spanish biopharmaceutical company founded in 1999 and headquartered in Madrid. It focuses on research, development, and manufacture of products for allergy diagnostics and allergen immunotherapy (ASIT). Firms in this sector sit at the intersection of clinical research, regulated manufacturing, and healthcare supply chains. They routinely handle scientific and technical documentation, quality and regulatory records, commercial contracts, and — depending on their operations — information linked to employees, collaborators, healthcare providers, and sometimes patients or study participants.

A breach affecting such an organisation is consequential because the data environment often mixes proprietary research, supply and distribution details, and personal or professional identifiers. Disruption can affect not only corporate continuity but also trust among clinicians and partners who rely on diagnostic and immunotherapy products. The listing does not by itself prove operational impact or patient-facing harm; it does place the company in a category where both intellectual property and personal data are typically sensitive.

What data was at risk

The facts name the exposed material only as internal files exfiltrated in a ransomware attack. No inventory of file types, no record counts, and no confirmation of customer, patient, or employee datasets have been published in the material provided. Exact contents therefore remain unconfirmed.

Organisations of this kind commonly hold research and development files, manufacturing and quality documentation, regulatory correspondence, internal email and administrative records, and human-resources or partner data. Whether any of those categories were among the files Deadlock claims to have taken is not established publicly. Readers should treat specific assumptions about medical records, payment card data, or named individuals as unverified until Diater or competent authorities say otherwise.

Why it matters

For individuals, the practical risks of internal corporate files appearing in a ransomware claim include misuse of contact details, targeted phishing that references real colleagues or projects, and — if personal or health-related identifiers were present — longer-term identity or privacy harm. For the organisation, consequences can include regulatory notification duties, contractual issues with partners, and the cost of investigation and remediation. None of these outcomes is confirmed solely by a leak-site listing; they are the ordinary stakes when exfiltration is alleged in a regulated health-related sector.

Concrete points to keep in view:

Were you affected?

If you work with Diater, receive its products, or have shared personal or professional data with the company, treat the situation as a prompt for ordinary caution rather than panic. Watch for unexpected messages that lean on internal names, projects, or allergy-related topics. Prefer official channels when checking whether the company has issued notices. Consider updating passwords on work-related accounts, enabling multi-factor authentication where available, and monitoring financial or medical accounts for unusual activity if you believe sensitive identifiers could have been involved. Public detail on this incident remains limited; official updates from Diater or Spanish authorities would supersede third-party claims.

You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach datasets, which may help you decide what to secure next.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyDiater security record
64/100
DoxxScan™ · Moderate doxx risk
B- 76Above-average record

1 reported incident on record.

See Diater’s full breach history →

More recent breaches

Picassent Listed by Deadlock Ransomware GroupJuly 10, 2026Takis srl Listed by Deadlock Ransomware GroupJuly 28, 2026Carrier AB Listed by Deadlock Ransomware GroupJuly 25, 2026Hi̇dromek Listed by Deadlock Ransomware GroupJuly 25, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Diater Listed by Deadlock Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by deadlock — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram