On March 29, 2026, the Spanish company lacor.es appeared on the leak site of the ransomware group ALP-001. The listing includes 182.71 GB of internal files that attackers say they exfiltrated during a ransomware incident. The group set a public deadline of April 8, 2026 and posted a mocking note about wanting “some fun” with the small company’s data.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch lacor.es
Get alerted the next time lacor.es files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about lacor.es’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting on the ALP-001 leak site describes lacor.es as a Spanish entity with roughly $9 million in revenue. The posted data consists of internal files rather than a structured database of customer records. No exact number of individuals affected has been released. The sample files shown on the leak page have not been independently verified by third parties, but the incident follows the group’s standard pattern of publishing stolen material when ransom demands go unmet.
Why This Matters for You and Your Family
Even when a breach targets a business, the files often contain documents that name suppliers, partners, employees, or customers. If your personal or family information appears in contracts, invoices, HR records, or email correspondence, it can surface in follow-on attacks. Credential leaks from such incidents frequently cascade into account takeovers on personal email, banking, and social media. Children’s names, school details, or family addresses sometimes sit inside the same folders, giving attackers easy starting points for harassment or identity theft aimed at your household.
The Doxxing and Identity-Chain Risks
Stolen internal files can link usernames, email addresses, phone numbers, and real-world identities in ways that are not obvious at first glance. Attackers chain these fragments across dozens of platforms to build full profiles. A single exposed work email can lead to personal accounts, and from there to gaming logins or family photos. Once the chain exists, doxxing escalates quickly—harassment, swatting, or extortion become realistic threats. Credential reuse across work and home systems makes the jump from corporate breach to personal compromise almost automatic.