← Ferrovial

2026 Ferrovial — AiLock ransomware leak-site claim (unverified; Jul 15)

2026 Unknown records affected Share on X

Data compromised

Actor listing does not publish an attested victim count or field inventory in open ransomware.live / tracker summaries reviewed at catalog time—unverified

Technical writeup

Unverified leak-site / extortion claim — observed July 15, 2026. Ransomware.live discovered Ferrovial on the AiLock leak site at approximately 09:20 UTC on July 15, 2026, describing the victim as a Spain-headquartered infrastructure and mobility operator (toll roads, construction, concessions). ThreatMon ransomware monitoring and HookPhish also flagged the listing. Ferrovial had not issued a matching public incident confirmation at indexing time, and no attested recordsAffected figure was available. BreachHistory indexes recordsAffected 0 labeled unverified pending company or regulator attestation.

Root cause

Unverified AiLock ransomware/extortion leak-site listing against Ferrovial S.A., the Spain-based global infrastructure and mobility operator

References