Ransom! Mecanizados y Montajes Aeron,áuticos (mymgroup.es) (MAY-2026)

Ransom! Mecanizados y Montajes Aeron,áuticos (mymgroup.es) (MAY-2026)
Incransom ransomware is claimed to have compromised Mecanizados y Montajes Aeronáuticos (mymgroup.es), an aerospace metallic components manufacturer serving major Tier 1 and OEM programs globally, allegedly exfiltrating approximately 100GB of confidential documents and business-critical data including clients information, NDAs, financial records, operations, corporate agreements, and development and transaction databases. The impacted country is #Spain

Incident Details

  • Victim: Mecanizados y Montajes Aeron,áuticos (mymgroup.es)
  • Sector: Manufacturing
  • Country: ES
  • Actor: incransom
  • Source: http://incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion/blog/disclosures/6a0f5600d152110a6a4f6aa3
  • Discovered: 2026-05-23T13:22:39.943279+00:00
  • Published: 2026-05-23T12:00:00+00:00

Information

  • Specializes in manufacturing metallic components and subassemblies for aerospace applications, supporting major Tier 1 and OEM programs worldwide.
  • Focused on excellence through advanced technology, strong infrastructure, and a skilled workforce to ensure high-quality production and on-time delivery.
  • Recognized as an innovative SME with active research and development efforts in the aerospace and industrial sectors.
  • Counts major companies such as Airbus, Boeing, Embraer, and Leonardo among its clients.
  • Claimed leak size: 100GB.
  • Allegedly collected confidential documents, client data, NDAs, financial data, operational records, corporate data, business agreements, development materials, and financial databases.
  • Also claimed access to all transactions, all clients, and other highly important information.

Disclaimer: This post is based on public claims made by the ransomware group "incransom". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live