Quick Summary
AllegedExecutive Summary
INC Ransom has listed SECOND HOUSE, a hospitality company based in Spain, on its leak site as of September 21, 2026. This listing was identified by SOCRadar’s Dark Web Monitoring service. This incident is notable as it marks the first time INC Ransom has targeted a Spanish hospitality firm within the past 60 days, representing a geographic deviation from their typically North American focus. While ransomware groups often target hospitality businesses due to their extensive customer data and operational dependencies, this specific targeting of a Spanish entity by INC Ransom is an outlier compared to their recent operational patterns. Over the 60 days preceding this listing, INC Ransom claimed a total of 68 other victims. Their primary targets have historically been in the Manufacturing, Professional Services, and Healthcare sectors, predominantly in the United States and Canada, with some activity in Malaysia. Previous victims in the hospitality and European sectors include Asfaltos y Pavimentos S.A. (Asfalpasa), Roan Luxury Camping Holidays, and The HOP. Although the European hotel sector is not entirely new to ransomware attacks, INC Ransom’s recent increased focus on this area, including this Spanish victim, suggests a potential expansion or shift in their operational strategy.
Technical Analysis
A stealer-log query was performed for the domain secondhouse[.]es. The results of this query were empty, meaning no direct records were found linking credentials associated with this domain to known infostealer logs within the queried dataset. It is important to note that this result does not definitively confirm that the organization is unaffected by credential compromise. The stealer-log query was paginated and bounded, meaning that credentials could still exist under a different subdomain, be associated with personal email aliases used by staff, or reside on third-party booking platforms not included in the sampled data. Therefore, the absence of positive findings in this specific query should be interpreted as a lack of current evidence rather than a complete exoneration from potential credential exposure. Such exposed credentials, if they exist through other means, could potentially be leveraged by threat actors for initial access, credential stuffing, or further lateral movement within the victim’s network to support ransomware deployment. The presence of exposed credentials on the dark web, even if not immediately linked to a specific stealer-log feed, can significantly lower the barrier for threat actors. This can lead to unauthorized access to corporate accounts, Microsoft 365 environments, VPNs, or other remote access portals. Continuous monitoring of dark web sources for mentions of SECOND HOUSE or related domains, along with proactive credential hygiene practices such as regular password rotation and multi-factor authentication enforcement, remain critical defensive measures.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.