Relesa Listed by Deadlock Ransomware Group: What Was Exposed & What To Do
Relesa was listed by the Deadlock ransomware group on July 25, 2026, with internal files reported exfiltrated in the attack; the number of individuals affected remains undisclosed. Users are advised to check any Relesa-related accounts or services they use and to follow the organisation’s guidance on protective steps.
People connected to Relesa — employees, business partners, or users of systems tied to its operations — may be wondering whether their information was caught up in a claimed ransomware incident. Public reporting indicates that the company was listed by the Deadlock ransomware group, with internal files said to have been taken. The number of people affected remains unknown, and many operational details have not been confirmed in open sources. For anyone who deals with the firm or its related platforms, the practical concern is straightforward: stolen internal material can expose business relationships, credentials, or personal details that later appear in fraud or further attacks.
What is known so far is limited. The listing was reported on July 25, 2026. Beyond the claim that internal files were exfiltrated in a ransomware attack, specifics such as the exact timing of intrusion, the full scope of systems involved, or independent confirmation of the theft have not been laid out in the available record. That uncertainty does not remove the need for caution; it simply means affected individuals should treat the situation as a credible risk until clearer information emerges.
What happened
According to public breach reporting, Relesa was listed by the Deadlock ransomware group. The reported summary states that internal files were exfiltrated in a ransomware attack. No confirmed figure has been given for how many people were affected, and the precise method of initial access, the duration of any intrusion, and the full inventory of systems touched remain undisclosed.
Ransomware incidents of this type typically involve unauthorized access followed by encryption of systems and the theft of data used as leverage. In this case, the public record centers on the group’s listing of the organization and the assertion that internal files were taken. Independent verification of the volume or sensitivity of those files has not been provided in the facts available. Readers should regard the leak-site listing as a claim by the group rather than a fully corroborated technical report.
The group behind it: Deadlock
Deadlock is a ransomware operation known in public cybersecurity reporting for double-extortion tactics: encrypting victim environments while also copying data and threatening to publish or sell it if demands are not met. Groups operating in this model commonly advertise victims on dedicated leak sites, post samples or file listings to increase pressure, and sometimes auction or release material when negotiations stall. Deadlock has been associated with opportunistic targeting across multiple sectors rather than a single industry focus.
Public descriptions of the group emphasize relatively rapid listing of victims and the use of standard ransomware playbooks — initial access through common vectors such as compromised credentials or exposed services, followed by lateral movement and data staging. None of that general pattern should be read as a confirmed play-by-play of the Relesa incident. For this case, the only attribution in the record is the group’s own listing and the claim that internal files were exfiltrated. No statements from Deadlock beyond that listing are included in the facts, and no ransom amount, negotiation detail, or proof package has been described here.
Relesa and its sector
Relesa, also referred to in reporting as Grupo Relesa, is described as a multinational Spanish company specializing in the fabrication of rejillas metálicas, commonly known as tramex or metal gratings. These products are used in industrial flooring, walkways, drainage, and related construction and infrastructure applications. Organizations in this manufacturing niche typically maintain supplier and customer records, engineering or order data, logistics information, and internal administrative systems.
The same reporting notes a connection to the digital platform and client portal of Reginald Lee SA, described as one of the official distributors of major Coca-Cola products in Argentina. That linkage, if accurate, means Relesa’s technology or service footprint may touch distribution, portal access, or related commercial systems beyond pure metal fabrication. A breach affecting such an organization matters because industrial and distribution firms often hold concentrated business data — contracts, contact lists, operational schedules, and credentials for partner portals — that can be reused in fraud, supply-chain disruption, or secondary attacks on customers and suppliers.
What data was at risk
The facts name the exposed material only as internal files exfiltrated in a ransomware attack. No further breakdown — such as whether the files included employee records, customer databases, financial documents, portal credentials, or technical drawings — has been disclosed. The number of individuals tied to those files is unknown.
Companies of this type commonly store personnel information, vendor and client contact details, invoices, shipping data, and access credentials for internal or partner systems. When a digital platform or client portal is part of the environment, session data, account identifiers, or support correspondence can also be present. Because the exact contents remain unconfirmed, it is not possible to state which of these categories, if any, were actually taken. The responsible position is to assume that internal business material may be in unauthorized hands until the organization or independent investigators provide a clearer inventory.
The real-world impact
For individuals, the main risks are secondary misuse of any personal or contact data that may have been inside the internal files. That can include targeted phishing that references real business relationships, attempts to reset accounts using known email addresses, or social-engineering calls that sound legitimate because they cite genuine company details. Employees and partners may also face credential-stuffing attempts if work emails or reused passwords appeared in the material.
For the organization, consequences can include operational disruption from encrypted systems, loss of confidentiality around commercial arrangements, regulatory notification duties depending on jurisdiction and data types, and erosion of trust among distributors, customers, and suppliers. If portal or platform components linked to distribution activities were involved, there is an added possibility of knock-on effects for partners who rely on those systems. None of these outcomes is confirmed in detail by the public facts; they are the ordinary range of harms that follow claimed exfiltration of internal corporate files.
What to do if you're exposed
If you have a relationship with Relesa, Reginald Lee SA, or related portals, treat unsolicited messages that reference the company with extra skepticism. Change passwords on any accounts that shared credentials with work systems, enable multi-factor authentication where it is available, and monitor bank and credit activity for unusual activity. Prefer official channels when verifying whether your data was involved rather than clicking links in unexpected emails or messages.
Keep records of any suspicious contact and report clear fraud attempts to the relevant authorities. You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. That step does not confirm or rule out involvement in this specific incident, but it can highlight whether your address appears in other circulated collections and help you prioritize further protections.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Schaad Listed by Deadlock Ransomware GroupVinilon Listed by Deadlock Ransomware GroupKemek Listed by Deadlock Ransomware GroupBioResearch Listed by Deadlock Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Relesa Listed by Deadlock Ransomware Group →
Publicly posted by deadlock — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.