Club Lleuresport
Attack Intelligence
Club Lleuresport was compromised in a ransomware attack attributed to qilin in October 2025. The organization, operating in the Hospitality and Tourism sector in Spain, was added to the group's data leak site as part of an extortion campaign.
qilin operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.
Club Lleuresport is a versatile organization based in Barcelona dedicated to leisure management, promoting culture, education, and sports for everyone. Since 1992, it has managed various public and private facilities, including civic centers ...
Intelligence correlations link this incident to 1 vulnerability(ies) including CVE-2026-0257, which may have been leveraged as initial access vectors or for lateral movement.