ROXU
bd_865f2d7273a89500 · schema v1 · pii pii-v1
Full breach record for ROXU →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Spacebears on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
Grúas Roxu, established in 1978, is the parent company of the Roxu Group and currently made up by the following companies: ROXU, PLAAS, IGR, IDEA and DURRUTI cranes. Since it was established in 1978, Grúas Roxu has been growing to become the leading company in Asturias and one of the top lifting machinery rental companies in Spain. Grúas Roxu is a service company, its activity consisting in the rental of lifting machinery with an operator, focussing on advisory and rental services regarding self-propelled mobile cranes, mobile personnel lifting platforms, self-loading crane trucks, specialised transport, studies and planning of civil and public work assemblies, industrial assemblies, etc. Our objective is very clear: to keep growing in a constant and sustainable manner while continuing to be a national reference in our sectorThanks to Gesimde Asociados S.L, Ausil, Esnova. The leak was made possible by these companiesDatabasePersonal information of employees and clientsFinancial documents https://gruporoxu.com/en/
Source provenance
- Source URL
- https://www.ransomware.live/id/Uk9YVUBzcGFjZWJlYXJz
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 5, 2025
- Raw hash
- a84516f827b9100405501cc5d10065e7210da0d72911c2d28ae49c1e7bfc4863
Reporting entity
- Name
- spacebears
Victim entity
- Name
- ROXUnorm: roxu
- Domain
- gruporoxu.com
- Industry
- Constructionllm
What this source establishes
- Source ceiling
- A leak-site claim can't tell us: discovery date · materiality · notification · affected count · confirmed data types · compliance clock. These stay blank until a regulatory filing or victim disclosure lands.
- Attack vector
- Ransomware· spacebears
- Threat actor
- SpacebearsExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.