Espac Data Breach

Alleged

Ransomware claim involving Espac.

Published: Aug 23, 2026 The Gentlemen
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Espac
Industry
Technology
Threat Actor
The Gentlemen
Date of Incident
Aug 23, 2026

Executive Summary

Espac, a technology company based in Chile, was identified as a victim of the ransomware group The Gentlemen on August 23, 2026, as listed on their leak site. The company operates within the Chilean market, providing technology and IT services. The simultaneous listing of Espac and another Chilean entity, Layher, by The Gentlemen on the same date suggests a potential coordinated campaign or a shared initial access vector targeting organizations within Chile. In the preceding 60 days, The Gentlemen has claimed approximately 227 victims, with Manufacturing, Technology, and Other sectors being their most frequently targeted industries. The United States, Germany, and the United Kingdom are the primary countries affected by this group. While Volktek, LOG Systems, and dlp motive are also technology victims, Layher’s inclusion as a manufacturing entity alongside Espac’s technology sector presence, and their shared Chilean origin, highlights a possible pattern of targeting within Chile, potentially stemming from a common access strategy.

Technical Analysis

SOCRadar’s analysis of The Gentlemen’s activities, specifically querying the domain `espac.cl` against stealer-log telemetry, yielded no matching records in the analyzed dataset. It is crucial to note that a lack of findings in a paginated sample does not definitively confirm that the organization is unaffected. Potential data may exist under alternate corporate domains, be associated with personal email aliases, or have been indexed subsequent to the query. Furthermore, credentials may have been compromised and rotated prior to their inclusion in the queried datasets. Infostealer-harvested credentials are a prevalent initial access vector for ransomware operations. While this specific query did not reveal direct evidence of such compromise for Espac via the `espac.cl` domain, the absence of such evidence does not rule out its possibility. The Gentlemen’s known operational methods include phishing, exploitation of exposed VPN appliances, and the use of recycled credentials. Organizations are therefore advised to audit authentication logs, implement multi-factor authentication on all internet-facing services, and consider the leak site listing as a strong indicator that the threat actor possesses considerable operational intelligence regarding the target.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.