MONTERO & SEGURA Listed by madliberator Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The MONTERO & SEGURA Listed by madliberator Ransomware Group (reported July 12, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
In a threat landscape where ransomware groups routinely list professional-services firms on dark-web leak sites to pressure payment, the appearance of a Spanish legal practice among recent claims is a reminder that even specialised, mid-sized organisations remain targets. On 12 July 2024 the ransomware group known as madliberator publicly listed MONTERO & SEGURA, asserting that it had exfiltrated internal files during a ransomware attack. The number of people affected remains unknown, and independent confirmation of the claim has not been published.
For clients, counterparties and employees of a firm that handles court representation for banks, public bodies and private companies, any such listing raises immediate questions about the confidentiality of legal and financial records. Public detail is limited; what follows is an account grounded solely in the available facts and established knowledge of the actor and the sector.
Breaking down the breach
According to the listing dated 12 July 2024, madliberator claims to have conducted a ransomware attack against MONTERO & SEGURA and to have exfiltrated internal files. No further technical detail—such as the initial access vector, the encryption status of systems, the volume of data taken, or the precise date of intrusion—has been disclosed in the public record. The number of individuals whose information may have been involved is listed as unknown. The organisation itself has not, in the material available, issued a detailed public statement confirming or denying the claim. In short, the incident is known principally through the group’s leak-site assertion that internal files were removed.
Ransomware operations of this type typically combine encryption of operational systems with the threat of publishing stolen data if a ransom is not paid. Whether encryption occurred here, whether negotiations took place, or whether any data has actually been released beyond the listing itself remains unconfirmed. The sole concrete assertion on record is that internal files were exfiltrated.
The group behind it: madliberator
madliberator is a ransomware operation that has appeared on public leak sites in recent years. Like many contemporary groups, it follows a double-extortion model: systems are encrypted and data is copied, after which the victim is threatened with publication unless payment is made. The group maintains a dedicated leak site where it posts the names of organisations it claims to have compromised, sometimes accompanied by sample files or countdown timers. Public reporting on madliberator has characterised it as one of several opportunistic actors that target a range of sectors rather than specialising in a single industry.
In the present case the group claims that MONTERO & SEGURA suffered a ransomware attack resulting in the theft of internal files. That claim should be treated as an unverified assertion by the threat actor until corroborated by the organisation, law-enforcement statements or independent forensic reporting. No additional statements attributed to madliberator about this specific victim—such as ransom demands, data volumes or release schedules—appear in the facts available.
About MONTERO & SEGURA
MONTERO & SEGURA operates as Segura Procuradores SLP, a professional limited company dedicated to the practice of procura—court representation and procedural work—across Spain. Its offices are located in Barcelona and Madrid; the Barcelona headquarters sits within a purpose-built judicial complex that allows the firm to respond rapidly to clients and instructing lawyers up to the close of court business. The firm’s client base includes major banks, credit institutions, public bodies and private companies.
Procura firms occupy a critical position in the Spanish legal system: they manage filings, notifications, deadlines and representation before the courts on behalf of lawyers and their clients. As a result they routinely handle sensitive procedural documents, client identifiers, financial details linked to litigation or enforcement, and correspondence with public authorities. A breach affecting such an organisation therefore carries implications that extend beyond the firm itself to the parties whose matters it administers.
What was likely exposed
The only data category named in the available facts is “internal files exfiltrated in a ransomware attack.” No inventory of specific document types, databases or personal-data categories has been published. Organisations of this kind typically hold client and matter files, court pleadings, identity and contact information for individuals involved in proceedings, banking or credit-related records connected to enforcement actions, and internal administrative material. Whether any of those categories were among the files claimed to have been taken remains unconfirmed.
Because the precise contents have not been disclosed, it is not possible to state as fact that particular personal or financial records were compromised. Readers should treat any subsequent claims about exact data types as requiring independent verification.
Why it matters
For individuals whose legal matters are handled by the firm, the principal risk is the potential exposure of sensitive procedural and personal information. Court documents can contain addresses, financial circumstances, family details and other material that, if published or sold, could facilitate fraud, harassment or reputational harm. Banks and public bodies that instruct the firm may face secondary exposure of commercial or administrative data, with possible regulatory and contractual consequences.
For the organisation itself, a ransomware incident—whether or not encryption occurred—can disrupt court deadlines, damage client trust and trigger notification obligations under Spanish and European data-protection rules. Even when the full scope remains unknown, the mere listing by a ransomware group creates lasting uncertainty for clients and counterparties who must decide how to protect themselves.
What to do if you're exposed
If you have reason to believe your information may have been held by MONTERO & SEGURA, begin by monitoring financial and credit accounts for unusual activity and consider placing fraud alerts with relevant Spanish credit agencies. Preserve any correspondence or case numbers that could help you identify whether your matter was active at the relevant time. Change passwords on any accounts that may have shared credentials or contact details with the firm, and enable multi-factor authentication wherever available. Because the exact data taken has not been confirmed, treat subsequent notifications from the firm or from regulators as the authoritative source of further guidance. As a practical first check, you can run a free exposure scan of your email address to see whether it has already appeared in known breach datasets; that step does not confirm involvement in this incident but can surface other exposures that warrant attention.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
msprocuradores.es Listed by madliberator Ransomware Groupmarthamedeiros.com.br Listed by madliberator Ransomware Groupctelift.com Listed by madliberator Ransomware Groupsuandco.com Listed by madliberator Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the MONTERO & SEGURA Listed by madliberator Ransomware Group →
Publicly posted by madliberator — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.