RANSOMWARE VICTIMTRANSPORTATION/LOGISTICSDUPLICATE CLAIM

Grupo Ruiz

www.gruporuiz.com
lynx📍 Spain (ES)📅 January 4, 2026
8
same group

Attack Intelligence

Grupo Ruiz was compromised in a ransomware attack attributed to lynx in January 2026. The organization, operating in the Transportation/Logistics sector in Spain, was added to the group's data leak site as part of an extortion campaign.

lynx operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

Grupo Ruiz is a leading firm in sustainable and innovative mobility with over a century of experience in transforming transportation responsibly and efficiently. The company operates a significant proportion of its fleet using compressed natural gas and electricity, making it a pioneer in sustainable transport solutions in Spain. They also focus on technological innovation through AI to optimize processes and enhance user experience.

Additional Details

Other Victims — lynx (8)

Quick Facts

CountrySpain (ES)
SectorTransportation/Logistics
Attack DateJan 4, 2026
Domainwww.gruporuiz.com
Intel Sourceransomware.live
StatusDUPLICATE CLAIM

Threat Group

lynx
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.