LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › grupoamper.com Listed by blackbasta Ransomware Group

HIGH severityUnverified claimHow we verify

grupoamper.com Listed by blackbasta Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·June 7, 2024
grupoamper.com Listed by blackbasta Ransomware Group

Reported June 7, 2024.

HIGH
Severity
June 7, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The grupoamper.com Listed by blackbasta Ransomware Group (reported June 7, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

People whose personal or work details sit inside a Spanish telecommunications firm’s systems now face a concrete possibility that those records have left the company’s control. On 7 June 2024 the ransomware group blackbasta listed grupoamper.com on its leak site, claiming it had taken roughly 650 GB of internal files. The number of individuals affected remains unknown, yet the categories of material named—R&D data, projects, users and employee information—mean that staff, partners and anyone whose details appear in those files could later encounter identity misuse, targeted phishing or competitive exposure of sensitive work.

Public detail is limited to the group’s own claim and the brief description that accompanied it. No independent confirmation of the intrusion method, exact timeline or full contents has been released. What follows therefore sticks strictly to the recorded facts while placing them in the context of how such incidents typically unfold.

Inside the incident

According to the listing dated 7 June 2024, blackbasta asserts that it exfiltrated internal files from grupoamper.com during a ransomware attack. The group states the total volume of data taken is approximately 650 GB and identifies the material as R&D data, projects, users and employee information. No further technical details—such as the initial access vector, the encryption status of systems, or any ransom demand—have been disclosed in the available record. The number of people whose data may be involved is listed as unknown. The organisation itself has not, in the facts provided, issued a public statement confirming or denying the claim.

Because the only source is the threat actor’s leak-site post, the incident must be treated as an unverified assertion until additional evidence appears. What is known is simply that the domain grupoamper.com was named, a data-size figure was given, and the categories of files were sketched in outline.

Inside blackbasta

Blackbasta is a ransomware operation that first drew wide attention in 2022. Like many contemporary groups it follows a double-extortion model: after gaining access it copies data before encrypting systems, then threatens to publish the stolen material if payment is refused. The group typically gains entry through compromised credentials, phishing or unpatched remote-access services, moves laterally inside the network, and stages large volumes of files for exfiltration. Its leak site has previously named organisations across manufacturing, professional services and critical infrastructure in Europe and North America. Claims posted there are the group’s own assertions; they are not independent verification that every file listed was in fact taken or that every victim was successfully compromised.

In the present case blackbasta claims to hold approximately 650 GB belonging to grupoamper.com. No additional statements attributed specifically to this victim—beyond the volume and the high-level file categories—appear in the recorded facts.

About grupoamper.com

Grupoamper.com is the online presence of Amper, a Spanish technology company whose roots reach back to 1951. That year the telecommunications engineer Antonio Peral founded Amper Radio in Salamanca. By the 1960s the firm was mass-producing radio and intercom equipment and had become a recognised specialist in its field. Today the organisation is headquartered at C/ Virgilio 2, Edificio 4, Ciudad de la Imagen, 28223 Pozuelo de Alarcón, Madrid. Its long history in communications hardware and related systems means it routinely handles technical designs, project documentation, customer and supplier records, and the personal data of employees and users of its products or services.

A breach at an organisation of this type therefore touches both commercial intellectual property and ordinary personal information. The company’s sector—telecommunications and electronic systems—makes the loss of R&D and project files particularly sensitive for competitive and contractual reasons, while any employee or user records raise the usual privacy and fraud concerns.

What data was at risk

The blackbasta listing states that internal files were exfiltrated and gives an approximate size of 650 GB. The categories named are R&D data, projects, users and employee information. Beyond those labels the exact contents remain unconfirmed. Organisations operating in telecommunications and electronics typically store engineering drawings, source code or design files, project schedules and contracts, directories of staff and contractors, and account details of customers or system users. Whether any of those specific items were among the 650 GB claimed by the group cannot be verified from the available facts. The number of individuals whose data may appear is unknown.

Why it matters

For employees and users, the presence of personal identifiers in the claimed haul creates a lasting risk of phishing, credential stuffing or identity fraud once the material is sold or published. For the company, exposure of R&D and project files can undermine competitive advantage, breach confidentiality clauses with partners, and invite regulatory scrutiny under European data-protection rules. Even if the files are never released publicly, the mere fact that an unauthorised party claims to possess them forces the organisation to investigate, notify regulators where required, and support anyone whose information may have been involved. Because the scale of personal impact is still listed as unknown, the practical burden falls on individuals to monitor their own accounts and correspondence for unusual activity.

Were you affected?

If you have ever worked for, contracted with, or supplied personal details to Amper or any of its related entities, treat the listing as a prompt to act rather than as proof that your data was taken. Concrete first steps include:

Public detail remains limited to the blackbasta claim of 7 June 2024. Further confirmation, if it emerges, will come from the company or from independent investigators. Until then, the safest course is to assume that any data once held by the organisation could be at risk and to take the ordinary protective measures listed above.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companygrupoamper.com security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See grupoamper.com’s full breach history →

More recent breaches

ayesa.com Listed by blackbasta Ransomware GroupApril 24, 2024bnext.nl Listed by blackbasta Ransomware GroupDecember 17, 2024plasmatherm.com Listed by blackbasta Ransomware GroupDecember 12, 2024medion.com Listed by blackbasta Ransomware GroupNovember 27, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the grupoamper.com Listed by blackbasta Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by blackbasta — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram