Unverified claim — July 15, 2026: Ransomware group AiLock listed Ferrovial, the Spain-based global infrastructure and mobility operator, on its leak site. Ransomware.live logged discovery around 09:20 UTC; ThreatMon and HookPhish flagged the same listing. Ferrovial had not confirmed an incident at indexing time.
What trackers show
The public listing identifies Ferrovial and describes its construction, toll-road, and concession businesses. It does not publish an attested count of stolen records or a detailed data inventory in the summaries we reviewed. Until Ferrovial, a European regulator, or an independent corpus analysis speaks, treat scale claims as unverified.
Why a Ferrovial listing is high-signal
Ferrovial sits on airports, highways, and major civil projects across markets. Even an unverified ransomware claim becomes bait for invoice fraud, fake "project delay" emails, and VPN resets aimed at contractors.
What this is not
This is not a confirmed outage post or an SEC-style disclosure. Leak-site marketing is the only public signal so far.
Action items
- Staff and suppliers: verify payment and change-order requests out-of-band.
- Lock down MFA on VPN, email, and project portals.
- Ignore "stolen Ferrovial dump" offers on forums and Telegram.
- Watch for phishing that correctly names active projects or concession brands.
Canonical record: Ferrovial 2026 on BreachHistory. Sources: Ransomware.live, HookPhish, ThreatMon.