pereclaver.org Listed by ralord Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
pereclaver.org was listed by the ralord ransomware group on March 28, 2025, after internal files were exfiltrated in an attack whose occurrence date has not been established. Individuals who have interacted with the organisation are advised to check for any contact from ralord and to take protective steps.
Ransomware groups continue to target organisations across healthcare, social care and non-profit sectors, often listing victims on dedicated leak sites after claiming to have stolen data. These incidents form part of a broader pattern in which threat actors pressure organisations by threatening to publish internal material if demands are not met. Against that backdrop, the listing of pereclaver.org by the group known as ralord has drawn attention to a Spanish non-profit that provides essential services.
Public reporting indicates that pereclaver.org was named on a ralord leak site on or around 28 March 2025. The group claims that internal files were exfiltrated during a ransomware attack. The number of people affected remains unknown, and many operational details have not been disclosed. The listing itself constitutes an unverified claim by the actors; independent confirmation of the full scope has not been made public.
What happened
According to available reports, the ransomware group ralord listed pereclaver.org among its claimed victims. The reported date associated with the listing is 28 March 2025. The actors state that internal files were exfiltrated as part of a ransomware attack. No public figure has been given for the volume of data taken, the precise method of initial access, or the duration of any intrusion. The number of individuals whose information may have been involved is listed as unknown. Beyond the group’s own claim on its leak site, further technical details about the incident remain undisclosed.
The group behind it: ralord
Ralord is a ransomware operation that has appeared in public threat reporting as a group that encrypts systems and exfiltrates data before posting victim names on a dedicated leak site. Like other actors in this category, it typically seeks to monetise both the encryption event and the threat of data publication. Public analyses of such groups describe common tactics that include phishing, exploitation of remote-access services, and the use of double-extortion pressure. Specific claims made by ralord about this particular organisation are limited to the listing itself and the assertion that internal files were taken; no additional statements from the group about pereclaver.org have been widely corroborated in open sources.
pereclaver.org and its sector
Pere Claver Grup is a private, non-profit organisation founded in 1948 in Barcelona, Spain. It employs more than 800 professionals and operates in the fields of mental-health care, social support and related community services. Organisations of this type routinely manage sensitive personal information, clinical records, staff data and operational documents necessary for the delivery of care. A breach affecting such an entity is consequential because the people it serves often include vulnerable individuals whose records, if exposed, could cause lasting personal harm. The non-profit status and public-service mission also mean that any disruption or reputational damage can affect service continuity and community trust.
What data was at risk
The only data category named in public reporting is “internal files exfiltrated in ransomware attack.” No further breakdown of file types, databases or record counts has been disclosed. Organisations operating in mental-health and social-care settings typically hold medical and psychological records, personal identification details, contact information, employment data and administrative correspondence. Because the exact contents of the material claimed by ralord have not been independently verified or itemised, it is not possible to state with certainty which of these categories, if any, were included. The precise nature of the exposed data therefore remains unconfirmed.
What's at stake
For individuals whose information may have been among the internal files, the primary risks include identity misuse, targeted phishing, and the unwanted disclosure of sensitive health or personal circumstances. Even limited internal documents can contain enough detail to enable fraud or social-engineering attempts. For the organisation itself, the stakes include potential regulatory scrutiny under data-protection rules, the cost of incident response and recovery, and erosion of confidence among service users and partners. Because the scale of any exposure is unknown, the full extent of these risks cannot yet be quantified, but the combination of ransomware and claimed data theft typically creates both immediate operational pressure and longer-term privacy concerns.
Were you affected?
If you have had contact with Pere Claver Grup—whether as a service user, family member, employee or partner—consider taking basic protective steps. Monitor financial and email accounts for unusual activity, enable multi-factor authentication where available, and treat unsolicited messages that reference the organisation with caution. Because the number of people affected has not been published, there is no official notification list to consult at this stage. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach datasets; such a check provides an additional, independent signal but does not replace official guidance from the organisation itself should further details emerge.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
NewHotel cloud Listed by nova Ransomware GroupPere Claver grup Listed by nova Ransomware GroupÉlan Sportif Nantes Listed by nova Ransomware Groupec-nantes.fr Listed by ralord Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the pereclaver.org Listed by ralord Ransomware Group →
Publicly posted by ralord — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.