NIS2 & DORA in force. EU AI Act next — book a demo
BREACHransomwarelive22 May 2026

Ransomware: krybit claims lasevillanita.com (ES) — Hospitality and Tourism

BREACH. Sourced from ransomwarelive, summarised by Matproof.

AI Analysis

What changed and what to do.

On 22 May 2026, a ransomware group known as krybit published a claim on the ransomware.live leak site, targeting the domain lasevillanita.com, which operates in the hospitality and tourism sector in Spain. This publication indicates that the threat actor has exfiltrated data from the organisation and is threatening to release it unless a ransom is paid. The incident is flagged under the BREACH framework, which is used by some EU member states to track and report data security incidents.

The primary affected organisation is lasevillanita.com, a Spanish hospitality and tourism business. However, this event serves as a broader warning for all EU hospitality and tourism entities, particularly those in Spain, as they are increasingly targeted by ransomware groups. Compliance teams in this sector should be alert to the heightened risk of data exfiltration and operational disruption.

Compliance teams should immediately verify whether their organisation has any third-party or supply chain links to the affected entity. They should also review their own ransomware preparedness, including offline backups, incident response plans, and data breach notification procedures under GDPR. If any data exposure is suspected, teams must assess whether a notification to the relevant supervisory authority is required within 72 hours. Finally, they should monitor ransomware.live and similar sources for any further disclosures that may impact their organisation.

View original at ransomwarelive

This summary is AI-generated for orientation purposes. For regulatory action, always consult the original source linked above.

More BREACH updates

Latest in BREACH.

← Back to all updates
Live regulatory monitoring

Never miss a compliance update.

Get weekly digests of DORA, NIS2, GDPR, MaRisk, and ISO 27001 changes — straight to your inbox. Free.

No spam. Weekly digest only. Unsubscribe anytime.

DORANIS2GDPRMaRiskISO 27001

Map this to your controls

Connect regulatory changes to your compliance work.

Matproof maps every regulator update directly to your controls and surfaces the ones that affect your organisation — across 21 frameworks.

Book a DemoBrowse all updates