RANSOMWARE VICTIMDUPLICATE CLAIM

Castilla

nova📅 November 2, 2025
8
same group

Attack Intelligence

Castilla was compromised in a ransomware attack attributed to nova in November 2025. The organization, operating in an undisclosed sector in Unknown, was added to the group's data leak site as part of an extortion campaign.

nova operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

Castilla is a company that operates in the Consumer Services industry. It employs 5to9 people and has 1Mto5M of revenue. The company is headquartered in Soria, Castille and Leon, Spain.

Additional Details

Other Victims — nova (8)

Quick Facts

Attack DateNov 2, 2025
Intel Sourceransomlook
StatusDUPLICATE CLAIM

Threat Group

nova
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.