On May 3, 2026, the Spanish administrative services firm Gestordes appeared on the leak site of the spacebears ransomware group. The attackers published more than 200,000 internal files containing clients’ passport and ID details, financial documents, and other sensitive records stolen during a ransomware incident at the company based in Ordes, A Coruña.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Gestordes
Get alerted the next time Gestordes files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Gestordes’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details of the Breach
Public reporting on the spacebears leak site describes the theft of internal files from Gestordes Administrative Management, which provides labor, tax, and accounting services to individuals and businesses. The exposed material includes personal identification records such as passports and national ID cards, along with financial documents. The total volume exceeds 200,000 files. No exact number of affected individuals has been confirmed, but the nature of the documents suggests that clients who used the firm’s services are at direct risk. The company’s own website acknowledges the importance of protecting both business and personal affairs, yet those records may now be publicly listed by the ransomware operators.
Why This Matters for You and Your Family
When a local administrative services provider loses control of ID copies and financial paperwork, the consequences reach far beyond the company. If you or anyone in your household has ever used a similar firm for tax returns, employment contracts, or accounting help, your personal data may now sit in an attacker’s archive. Passport numbers, national IDs, and financial records are exactly the material criminals need to open accounts, file fraudulent taxes, or impersonate family members. Children’s records, sometimes included in family tax files, can be especially damaging because they lack their own credit history and are harder to monitor.
Once this information leaves the original breach, it rarely stays contained. Copies spread across underground forums and can resurface months or years later.