Quick Summary
AllegedExecutive Summary
Aldaco Avance 2022 S.L., a Business Services organization located in Spain, has been identified as a victim by the Deadlock ransomware group. The listing appeared on the Deadlock group’s dark web leak portal on July 12, 2026, as detected by SOCRadar’s Dark Web Monitoring service. This places Aldaco Avance 2022 S.L. within the typical victim profile of the Deadlock ransomware group, which has a notable pattern of targeting organizations in the Business Services, Manufacturing, and Hospitality and Tourism sectors, particularly in Spain, Singapore, and Sweden.
Technical Analysis
SOCRadar’s investigation into initial access vectors for Aldaco Avance 2022 S.L. via stealer-log telemetry returned no direct records for the organization’s domain (aldacogrupoavance.es). However, this absence of evidence does not confirm a lack of compromise. It’s possible that credentials were harvested and used before the queried period, sourced from different feeds, located under alternative domains, or collected via personal email aliases. Credential harvesting remains a significant initial access method for ransomware groups like Deadlock, who commonly source credentials from underground marketplaces to gain unauthorized access to corporate networks. It is recommended that CTI teams maintain vigilance and implement robust credential hygiene practices.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.