On May 17, 2026, Spanish engineering firm Ingelan appeared on the leak site of the dragonforce ransomware group. The company, which provides security for information systems, communications architecture, and industrial automation, is claimed to have had internal files exfiltrated during a ransomware attack. While the exact number of people whose data may have been exposed remains unknown, anyone whose personal or professional information passed through Ingelan’s systems could be affected.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Ingelan
Get alerted the next time Ingelan files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Ingelan’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details of the Breach
Public reporting indicates that dragonforce listed Ingelan after breaching its networks and stealing internal documents. The leak site entry, hosted on an onion domain and tracked by ransomware.live, states the data was taken during a ransomware incident. No specific volume of records has been disclosed, and the precise types of files remain unclear beyond the broad description of internal files. Ingelan, founded in 1993 and based in Barcelona, specializes in securing complex communications and plant automation environments, which means the stolen material could include project documentation, client correspondence, or operational data.
At the time of publication, the group had not publicly named a specific ransom deadline for Ingelan, though dragonforce typically follows a double-extortion model of encryption followed by data-leak threats.
Why This Matters for You and Your Family
When a company that handles secure systems and communications is breached, the ripple effects reach ordinary people. If you or any member of your family has worked with Ingelan, used one of its client systems, or had personal details stored in its project files, that information may now sit on a criminal leak site. Internal files often contain names, email addresses, phone numbers, addresses, contract details, and sometimes copies of identification documents.