grupocadarso.com Listed by blackbasta Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The grupocadarso.com Listed by blackbasta Ransomware Group (reported May 4, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
For customers, employees and business partners of Grupo Cadarso, the appearance of the company on a ransomware group’s leak site raises immediate practical questions: whether personal or commercial information has left the organisation’s control, and what that could mean for privacy, fraud risk or day-to-day operations. Public detail remains limited, yet the listing itself is enough to warrant careful attention from anyone who has dealt with the firm.
On 4 May 2024 the ransomware group known as blackbasta claimed to have listed grupocadarso.com after a ransomware attack in which internal files were said to have been exfiltrated. The number of people affected is unknown, and no further confirmed inventory of the material has been released. The claim is unverified beyond the group’s own statement, but it places the Spanish family-owned business in the spotlight of a well-documented double-extortion campaign.
Breaking down the breach
According to the available record, blackbasta listed grupocadarso.com on or around 4 May 2024. The only data category named is “internal files exfiltrated in a ransomware attack.” No figure for the volume of data, no list of specific file types, no confirmation of encryption of production systems, and no statement of whether a ransom was demanded or paid have been made public. The number of individuals whose information may be involved is recorded simply as unknown. Timing of the initial intrusion, the vector used, and any subsequent containment steps remain undisclosed. In short, the public picture consists of a leak-site claim and a high-level description of exfiltrated internal material; everything else is unconfirmed.
The group behind it: blackbasta
Blackbasta is a ransomware operation that emerged in 2022 and has since been linked to numerous attacks on organisations across Europe and North America. Like many contemporary groups, it typically employs a double-extortion model: encrypting systems while also copying data and threatening to publish it if payment is not made. The group maintains a dark-web leak site where it posts victim names and, in some cases, sample files or larger archives. Its operators have been observed using common initial-access methods such as phishing, exploitation of unpatched remote-access services, and the purchase of credentials from initial-access brokers. Once inside a network they move laterally, escalate privileges, and stage data for exfiltration before deploying ransomware. Public reporting has associated blackbasta with attacks on manufacturing, logistics, professional services and hospitality firms, among others. In the present case the group claims to have listed Grupo Cadarso; that claim has not been independently verified by the company or by law-enforcement statements available in open sources.
grupocadarso.com and its sector
Grupo Cadarso is a family company founded in 1948 by Antonio Cadarso. It began by distributing watches and jewellery and has grown into two principal lines of business: watchmaking and hospitality. In watchmaking it distributes a selection of prestigious international brands across Spain, Portugal and Andorra. In hospitality, under the Condes Hotels brand, it operates landmark properties including Hotel Condes, Hotel España and the Monument Hotel. Organisations of this type routinely hold customer reservation and loyalty data, payment-related records, employee personnel files, supplier contracts, and internal financial and operational documents. A ransomware incident affecting such a firm therefore carries consequences both for guests and staff whose personal details may be involved and for the continuity of hotel and distribution operations that depend on those systems and records.
What was likely exposed
The only category explicitly named in the public record is “internal files exfiltrated in a ransomware attack.” No further breakdown—customer databases, employee records, financial ledgers, reservation systems or otherwise—has been confirmed. Companies operating hotels and brand-distribution networks typically maintain guest contact and booking information, staff payroll and identity documents, supplier agreements, and proprietary commercial data. Whether any of those categories were among the files blackbasta claims to have taken remains unconfirmed. Readers should treat any assertion of specific data types beyond the stated “internal files” as speculative until corroborated by the organisation or by independent investigation.
The real-world impact
If internal files containing personal or commercial information have been copied, affected individuals face the ordinary risks associated with data exposure: targeted phishing that references real bookings or employment details, identity-fraud attempts, and unwanted contact. For the organisation the consequences can include operational disruption while systems are restored, potential regulatory notification duties under European data-protection rules, contractual obligations to partners and brands, and reputational questions from guests and distributors. Because the precise contents and the number of people involved are unknown, the scale of these risks cannot yet be quantified; the prudent stance is to assume that any personal data held by the company could be in play until clearer information emerges.
Were you affected?
Anyone who has stayed at a Condes Hotels property, purchased watches through Grupo Cadarso’s distribution channels, or worked for or with the company should monitor bank and credit statements, be alert to unexpected emails or calls that reference past transactions, and consider placing fraud alerts with relevant credit agencies if they reside in jurisdictions that offer them. Changing passwords on accounts that may have shared credentials with company systems is a sensible immediate step. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets; such a check provides an additional, low-effort signal while official notifications, if any, are still pending.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
arunestates.co.uk Listed by blackbasta Ransomware Groupbathfitter.com Listed by blackbasta Ransomware Groupschuff.com Listed by blackbasta Ransomware Grouplornestewartgroup.com Listed by blackbasta Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the grupocadarso.com Listed by blackbasta Ransomware Group →
Publicly posted by blackbasta — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.