July 2026: Public water utility Acosol (Costa del Sol Occidental, Spain) confirmed a cyberattack detected June 28, 2026 that partially hit corporate IT and may have compromised some customer personal data. Days later, Qilin appeared on ransomware trackers listing Acosol—treat the leak-site marketing as unverified beyond the company's notice.
What Acosol said
According to La Opinión de Málaga, Acosol detected the incident on Sunday June 28, activated security protocols with internal and external specialists, and notified competent authorities including Andalusia's transparency and data-protection council.
Early analysis pointed to a malicious act affecting availability of certain information and possibly personal data of some customers or subscribers—basic identifiers, contact details, DNIs, contractual information, and potentially payment means. Acosol said it had no evidence of fraudulent misuse and told customers to scrutinize unusual payment or data requests. Contact for doubts: [email protected].
The Qilin listing
Ransomware.live indexed a Qilin victim page for Acosol discovered July 17, 2026. Open indexes reviewed for this entry did not publish an attested exfiltration volume or person count from that listing. Company confirmation covers the IT cyberattack and possible PII impact—not every claim a ransomware blog may later make.
Why a water utility matters
Even when drinking-water operations stay up, a hit to billing/CRM systems is enough for invoice phishing and identity fraud across an entire coastal service area.
What customers should do
- Pay only through official Acosol channels; ignore urgent "update your IBAN" messages.
- Assume DNI/contact data may be in play if you are an abonado—watch for identity and tax-related scams.
- Canonical record: Acosol 2026 on BreachHistory.
Sources: La Opinión de Málaga; Ransomware.live (Qilin / Acosol).