Fluge Audiovisuales Data Breach

Alleged

Ransomware claim involving Fluge Audiovisuales.

Published: Oct 5, 2026 Lamashtu
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Fluge Audiovisuales
Industry
Business Services
Threat Actor
Lamashtu
Date of Incident
Oct 5, 2026

Executive Summary

On October 5, 2026, the lamashtu ransomware group listed Fluge Audiovisuales, a Spanish company specializing in audiovisual event production and AV integration, on their leak site, claiming unauthorized system access and threatening data exfiltration. SOCRadar’s Cyber Threat Intelligence (CTI) division identified 25 compromised credential records associated with the domain fluge[.]es. These records span a significant period from January 2025 to September 2026, indicating an exposure window of 21 months. This extended period of data compromise, predating the lamashtu listing by nearly two years, suggests a deep-rooted vulnerability within the company’s systems. The nature of the exposure, involving both corporate credentials and workstation artifacts, points to significant potential for further intrusion and data exploitation. lamashtu has demonstrated a consistent pattern of targeting industrial, transportation, and service-sector organizations, with a notable concentration of victims in Germany, Spain, and Mexico. Fluge Audiovisuales joins other recent Spanish victims such as PROJAHN, TRANS LOGROÑO SOCIEDAD ANONIMA, Grupo Industrial Tauro, and Bender Tribunenbau, highlighting Spain as a key focus for lamashtu’s current campaign. This targeting aligns with the group’s preference for organizations that may possess valuable data or critical infrastructure, making companies in the audiovisual sector a potential target for their extortion tactics.

Technical Analysis

SOCRadar’s investigation uncovered 25 compromised records pertaining to fluge[.]es. This total comprises 8 corporate credential logs and 17 workstation compromise artifacts. The workstation artifacts are particularly concerning as they represent actual endpoint infections, rather than mere password exposures. This indicates that multiple Fluge employee machines were compromised by infostealer malware over an extended duration, leading to the harvesting of sensitive information including browser-saved credentials, session cookies, and VPN tokens. The observation of 21 months of workstation-level compromise provides a detailed intelligence profile for potential attackers. Ransomware operators actively seek out organizations with persistent endpoint leakage from stealer log archives, as this signifies a weak security posture and a partially established internal foothold. The presence of such extensive compromise suggests that adversaries could have gained deep visibility into Fluge’s corporate environment and client engagements. Endpoint forensics should be prioritized across all machines potentially affected by infostealer infections during the identified exposure window. A comprehensive credential reset is crucial, alongside active threat hunting to detect any remaining persistence mechanisms. Given the 21-month compromise period, it is essential to assume that adversaries may have maintained extended visibility into Fluge’s corporate environment and client engagements.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.