On January 31, 2025, the Spanish real estate website inmobiliariamaspormenos.com appeared on the leak site of the funksec ransomware group. The company, which sells bank-owned residential, commercial and industrial properties, may have had internal files stolen during a ransomware attack. While the exact number of people affected remains unknown, anyone who bought or inquired about property through the firm could have personal details now exposed.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch inmobiliariamaspormenos.com
Get alerted the next time inmobiliariamaspormenos.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about inmobiliariamaspormenos.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that funksec exfiltrated internal documents from the real estate platform before encrypting systems or demanding payment. The data includes files that typically contain customer names, contact information, property transaction records, identification documents and financial details used in purchases. The listing on the group's onion site states the breach occurred in late 2024 or early January 2025. No evidence has surfaced that the stolen files have been sold on other underground markets yet, but the mere publication on a ransomware leak page means the information is now publicly available to anyone who accesses the site.
Why This Matters for You and Your Family
If you or anyone in your household has ever purchased a home, submitted documents or even requested information from inmobiliariamaspormenos.com, your data may now be in the hands of criminals. Real estate records often include full names, addresses, phone numbers, email accounts, passport or national ID copies, bank details and signatures. Once leaked, this information rarely stays contained. Criminals combine it with other breaches to build complete profiles that can be used for identity theft, loan fraud, tax scams or targeted phishing. For families, a single exposed address or parent’s email can quickly pull in children’s details if school forms, family contracts or shared accounts were part of the transaction paperwork.
The Doxxing and Identity-Chain Risks
Stolen real estate files create dangerous links between your real identity and online handles. An email address from a property purchase can be cross-referenced with gaming accounts, social media or family forums. This forms what security analysts call an identity chain. A criminal who starts with your leaked home-buying records can locate your username on a child’s Roblox or Minecraft account, then use the same password or security questions elsewhere. Available reporting describes how these chains lead to doxxing, account takeovers and extortion. Even if you never reuse passwords, the combination of your address, phone number and family names gives attackers enough to impersonate you convincingly to banks, schools or government offices.