ONE Contact Listed by Deadlock Ransomware Group: What Was Exposed & What To Do
On July 10, 2026, the Deadlock ransomware group listed ONE Contact in connection with a ransomware attack in which internal files were exfiltrated. Individuals are advised to check whether their information was affected and take appropriate protective steps.
What happened
The incident came to light when the Deadlock ransomware group added ONE Contact to its leak-site listing. The group claims to have exfiltrated internal files during a ransomware operation against the company. No details on the timing of the intrusion, the volume of data involved, or the method of access have been disclosed. The number of people whose information may be affected is also not known.
Who is Deadlock?
Deadlock is a ransomware group that has appeared in public reporting as an actor that deploys encryption malware and maintains a leak site to pressure victims. Like similar groups, it typically claims to have stolen data before encryption and lists organisations that do not meet its demands. Public records show the group has targeted entities across multiple sectors in prior activity, though specific claims regarding ONE Contact remain limited to the listing itself.
ONE Contact and its sector
ONE Contact operates as a contact centre with its physical office on Calle Padilla in Barcelona, Spain, while managed from Sweden. The company provides customer service, telemarketing, and retention services primarily for clients in the Scandinavian market, including first- and second-line support and digital customer-service solutions. Organisations in this sector routinely process call records, customer interaction logs, and account-management data on behalf of their clients.
What data was at risk
The Deadlock listing states that internal files were exfiltrated. No further breakdown of file types or contents has been released. Contact centres of this kind commonly hold operational records such as call logs and client account details, yet the precise categories of information involved in this incident remain unconfirmed beyond the general reference to internal files.
What's at stake
Exposure of internal operational files can reveal details about client relationships and day-to-day processes, which may affect both the organisation and the customers it serves. For individuals, any personal data contained in those files could be used for targeted social-engineering attempts or account takeovers. The organisation faces potential disruption to client contracts and the costs associated with investigating and containing the intrusion.
If your data was in this breach
Monitor accounts linked to any services handled by ONE Contact for unusual activity and consider enabling additional verification steps where available. Individuals can also run a free exposure scan of their email address against known breach data to check whether their information appears in public listings from this or other incidents.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Carrier AB Listed by Deadlock Ransomware GroupAldaco Avance 2022 S.L. Listed by Deadlock Ransomware GroupSchlenker and Cantwell, P.A. Listed by Deadlock Ransomware GroupConsulting Valladolid Listed by Deadlock Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the ONE Contact Listed by Deadlock Ransomware Group →
Publicly posted by deadlock — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.