Cyber Incident Victim: MasMovil
Date:
Jul 2021
Location:
Spain
Summary
A Spanish telecommunications provider suffered a ransomware attack by the REvil gang, which claimed to have exfiltrated sensitive company data including databases, backups, reseller information, and scoring documents. The attackers published screenshots of allegedly stolen directories as proof of compromise, though specific operational disruptions or financial demands related to this incident were not detailed in available reports. This breach occurred amid REvil's broader ransomware campaign activity, which included simultaneous high-profile attacks on other organizations. The group typically demanded substantial cryptocurrency payments in exchange for decryption keys and suppression of stolen data, though the exact ransom terms for this specific intrusion remain unspecified.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On or around July 4, 2021, the REvil ransomware gang targeted MasMovil, one of Spain's largest telecommunications operators. The attackers infiltrated the company's systems and exfiltrated sensitive data, including databases and operational documents. REvil publicly claimed responsibility for the breach by posting a message on its Tor-based leak site, accompanied by screenshots purportedly showing stolen directories such as Backup, RESELLERS, SCORING, and PARLEM. These folders suggested access to business-critical systems containing partner information, customer scoring data, and backup repositories. The ransomware group stated, "We have downloaded databases and other important data," though MasMovil did not publicly confirm the scope of data compromise at the time of reporting. The incident coincided with REvil's simultaneous execution of a global supply-chain attack through Kaseya VSA software, which impacted over 1,000 organizations.

REvil's attack on MasMovil occurred during a period of heightened activity for the group, which had escalated its ransom demands in parallel operations. While the gang initially demanded $44,999 per infected endpoint in the Kaseya incident, it later sought a single $70 million Bitcoin payment to decrypt all affected systems in that separate campaign. No specific ransom demand for the MasMovil breach was disclosed in available reporting. The publication of folder screenshots on REvil's leak site indicated an intent to pressure the telecom provider through potential data exposure, though no explicit deadline or extortion terms were detailed for this case. The breach exposed operational and potentially customer-related data, though MasMovil's public response and mitigation actions were not documented in the immediate aftermath. The incident highlighted REvil's focus on critical infrastructure sectors during mid-2021, leveraging double-extortion tactics against high-value targets.
