Feliubadaló Data Breach

Alleged

Ransomware claim involving Feliubadaló.

Published: Jul 15, 2026 Qilin
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Feliubadaló
Industry
Retail
Threat Actor
Qilin
Date of Incident
Jul 15, 2026

Executive Summary

Feliubadaló, an organization based in Spain, was identified as a victim on the qilin ransomware group’s dark web portal on July 15, 2026. This listing was discovered through SOCRadar’s Dark Web Monitoring service. While the specific industry sector for Feliubadaló was not detailed in the source material, its online store domain suggests a consumer-facing retail presence. The inclusion of Feliubadaló among qilin’s victims places it within a broad population of targets and aligns with the group’s consistent activity against European entities. In the 60 days preceding this listing, qilin claimed 107 other victims, positioning it as the most active actor currently tracked. The group predominantly targets the business services, manufacturing, and consumer services sectors. Geographically, its victims are primarily located in the United States, Australia, and Germany. There are notable overlaps with Feliubadaló’s profile in recent qilin listings; other Spanish organizations or consumer-focused businesses that have been targeted include URH Hoteliers, DISTINET MURCIA SL, THL, and TitanTV, Inc. Feliubadaló fits into qilin’s ongoing pattern of targeting European consumer-oriented businesses, despite the group’s overall activity volume being skewed towards the U.S.

Technical Analysis

SOCRadar’s analysis, utilizing stealer-log telemetry concerning the feliubadalo.com domain, revealed a notable credential exposure. Approximately 25 credentials were found associated with the domain. These consisted of two corporate usernames from third-party (supplier/partner) domains observed on the target’s site, and roughly twenty-three customer or external-user accounts on organization-owned URLs. Importantly, no employee credentials on internal systems were identified in this particular query. The primary finding is the exposure of customer account logins on the online store, indicating a risk of account takeover against the consumer-facing platform, rather than a direct compromise of corporate systems. The dominant pattern observed is customer account takeover risk and supplier-related exposure. The data shows a freshness window extending from June 2025 through July 15, 2026, suggesting persistent and current exposure of customer credentials. While this stealer-log evidence does not definitively confirm a link to qilin’s intrusion methods, such harvested credentials are a well-documented initial access vector for ransomware groups. Operators often source fresh logs, validate corporate credentials, and use them to gain access to systems via Microsoft 365, VPNs, or remote-access portals before deploying ransomware. Therefore, the observed exposure points more towards customer account compromise and potential fraud rather than a direct corporate cyber-attack path. Given the findings, CTI teams should treat the revealed customer-facing exposure as a primary concern for fraud and notification. Investigation into the two supplier/partner accounts observed on the domain is recommended. Continuous monitoring for corporate credential exposure that may fall outside the scope of this specific query is also advised.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.