LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › insoca.es Listed by qilin Ransomware Group

HIGH severityUnverified claimHow we verify

insoca.es Listed by qilin Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·August 20, 2025
insoca.es Listed by qilin Ransomware Group

Reported August 20, 2025.

HIGH
Severity
August 20, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

insoca.es was listed by the Qilin ransomware group on August 20, 2025, with internal files reported as exfiltrated; the date of the intrusion itself has not been established. Individuals who may have interacted with the organisation should review any notices from insoca.es and follow recommended security steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to target mid-sized industrial firms across Europe, using double-extortion tactics that combine encryption with the public threat of data leaks. In this environment, even specialised manufacturers can find themselves listed on criminal leak sites, raising questions for employees, partners and customers about what information may have left the organisation.

On 20 August 2025, the Spanish company insoca.es appeared on a listing claimed by the Qilin ransomware group. Public reporting indicates that internal files were exfiltrated during a ransomware attack. The number of people affected remains unknown, and many operational details have not been disclosed. The listing itself is a claim by the group rather than an independently confirmed disclosure.

Breaking down the breach

According to available records, insoca.es was listed by the Qilin ransomware group on 20 August 2025. The incident is described as a ransomware attack in which internal files were allegedly exfiltrated. No precise timeline of the intrusion, no confirmed method of initial access, and no verified volume of data have been made public. The number of individuals potentially affected is listed as unknown. Beyond the group’s claim that internal files were taken, further technical or forensic detail has not been released in the public reporting associated with this listing.

One document referenced in connection with the matter is a gas bill issued by DISA ENERGY S.L.U. to Cartonajes Izquierdo S.A. covering the period 1–30 June 2025. Whether this file formed part of the material claimed by the group, and what other files may have been involved, has not been independently verified. Public detail on the full scope of the exfiltration remains limited.

Who is qilin?

Qilin is a ransomware operation that has been active for several years and is widely documented as operating a ransomware-as-a-service model. Affiliates typically gain access to networks, encrypt systems, and exfiltrate data before demanding payment. The group is known for publishing victim names and sample files on dedicated leak sites when negotiations stall, a practice often called double extortion. Prior public activity has included targets across manufacturing, professional services and other commercial sectors in multiple countries. In the present case, the appearance of insoca.es on the group’s listing constitutes a claim by Qilin; it does not by itself confirm the full extent of any compromise.

Who is insoca.es?

insoca.es is described in available reporting as a family-owned business operating with a high level of technology in the corrugated cardboard sector. Companies of this type typically design, manufacture and supply packaging materials used by a wide range of industrial and commercial customers. They commonly hold operational data, supplier and customer records, financial documents, and internal technical or production information. A ransomware incident affecting such an organisation can therefore touch both the firm’s own continuity and the commercial relationships that depend on its packaging supply chain.

What data was at risk

Public facts state that internal files were exfiltrated in the ransomware attack. No comprehensive inventory of the data types has been released, and the exact contents remain unconfirmed. Organisations in the corrugated packaging sector ordinarily maintain customer and supplier contact details, invoices, contracts, production schedules, quality records, employee information and utility or facilities documents. One document noted in connection with the listing is a gas bill from DISA ENERGY S.L.U. addressed to Cartonajes Izquierdo S.A. for June 2025. Beyond that reference and the general statement that internal files were taken, the precise nature and volume of any exposed material have not been disclosed.

The real-world impact

For individuals whose details may appear in internal business files, the practical risks include unwanted contact, phishing attempts that reference genuine commercial relationships, or the misuse of personal or financial information if such data were present. Because the number of people affected is unknown and the full data set has not been published, the scale of any personal exposure cannot yet be measured.

For the organisation itself, the consequences of a ransomware incident typically include operational disruption, recovery costs, potential contractual or regulatory obligations, and reputational questions from customers and partners who rely on continuous packaging supply. Family-owned industrial firms often operate with leaner IT resources than large multinationals, which can lengthen recovery timelines, though no specific assessment of insoca.es’s response has been made public. The listing by Qilin adds the further pressure of a public claim that data may be released if demands are not met.

Were you affected?

If you have had dealings with insoca.es or related entities in the corrugated cardboard sector, treat unsolicited messages that reference invoices, deliveries or internal documents with caution. Monitor financial accounts and change passwords on any accounts that may have shared credentials with work systems. Consider enabling multi-factor authentication where available. Readers can also run a free exposure scan of their email address to check whether their information has already appeared in known breach data sets. Official notifications, if any are issued by the company or by Spanish data-protection authorities, should be followed carefully for further guidance.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companyinsoca.es security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See insoca.es’s full breach history →

More recent breaches

Sintac Recycling Listed by qilin Ransomware GroupDecember 29, 2025Atarfil Listed by qilin Ransomware GroupOctober 11, 2025https://www.injusa.com/ Listed by qilin Ransomware GroupJuly 2, 2025Industrial Carrocera Arbuciense Listed by qilin Ransomware GroupApril 21, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the insoca.es Listed by qilin Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by qilin — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram