Three pro-Russian hacking crews claim to have obtained and exposed the identities of more than 400 Spanish and Ukrainian intelligence personnel attached to NATO structures, after breaching law enforcement and security databases in Spain and other NATO countries. The claim originates with the attackers themselves, relayed through Russian state media (Sputnik) and a Russian tabloid interview (Komsomolskaya Pravda, via Pravda ES), and was picked up by aggregator coverage at StoryChase. No Spanish government body, national CERT, or NATO entity has publicly confirmed the breach, and readers should treat the 400+ figure as an unverified attacker claim rather than an established count. What is independently documented by established security press is the surrounding pattern: Spain's Policía Nacional has made at least two arrests in the past several months tied to leaking sensitive official personnel data and to pro-Russia hacktivist infrastructure.
What Happened
According to Sputnik, the groups PalachPro, APTDesi, and NoName057(16) told the outlet they had breached law enforcement and security databases in Spain and other NATO member states, obtaining identity data on over 400 Spanish and Ukrainian intelligence officers linked to NATO. StoryChase reports the same core claim and adds that the attackers said the material was handed to Russian intelligence agencies to support operations against Western countries in Ukraine.
An actor using the handle APTDesi gave a fuller account to Komsomolskaya Pravda, reproduced by Pravda ES. He identifies himself as a Spanish citizen granted asylum in the Russian Federation, describes himself as an intelligence specialist rather than a purely technical operator, and says he maintains "a huge network of informants in Spain and Latin America" who open doors he then pivots through. He states that Spain and Europol have accused him of cyberterrorism and sabotage, that he published data on senior Spanish military intelligence officials in September 2025, and that Spanish media are currently staying quiet while, in his telling, "intelligence there is very nervous." He describes PalachPro as belonging to a separate grouping and operating largely as a lone actor. His stated objective is political: to pressure Spain and the West into ending support for NATO and Kyiv, "exclusively in the interests of Russia."
Every one of those details is self-reported by an actor with an explicit propaganda motive, published in Russian state-aligned outlets. The accounts do not conflict with each other so much as they all trace back to the same origin point, which is the weakest possible sourcing structure for a claim of this severity.
Against that, the independently reported record is narrower but firmer. The Record reports that Spanish National Police arrested a suspect in Granada province in late July 2026 for publishing personal data belonging to officials of the National Police, Civil Guard, Attorney General's Office, National Security Council, and INCIBE, Spain's national cybersecurity institute. Police searched the suspect's home, seized computer and electronic equipment now under forensic analysis, and described the incident as a large-scale disclosure that endangered both the individuals and their institutions. Police did not name the suspect or state a motive, and the investigation into whether a wider network amplified the data is ongoing. Separately, The Register reports that a man arrested in March 2026 in Palencia is suspected of ties to CyberArmy of Russia Reborn (CARR) and Z-Pentest, and of carrying out attacks on behalf of NoName057(16); that arrest followed an August 2025 FBI tip that he had provided logistical cover to help a Ukrainian CARR member flee to Russia via Poland and Belarus. Spanish authorities have not linked the Granada arrest to the intelligence-personnel claims, and no source connects the two cases.
What Was Taken
Per the attacker accounts carried by Sputnik, the leaked files include information on Spanish military personnel cooperating with NATO structures in Ukraine, plus individuals the hackers allege are linked to the SBU, the CIA, and MI6. The 400+ figure is the only number offered, and it appears identically across StoryChase and Sputnik because both trace to the same actor statements. No source provides a record schema, a sample, or an independent count.
The Granada case documented by The Record involves a different and better-attested dataset: personal information on officials across the National Police, Civil Guard, Attorney General's Office, National Security Council, and INCIBE, posted across multiple internet platforms. No volume figure was released for that leak either.
For scale context on the broader Spanish data-leak environment, the same reporting notes an earlier arrest of a 19-year-old in northeastern Spain accused of stealing and selling roughly 64 million personal records from nine companies. Adjacent unverified claims are also circulating: Roams reports an actor calling himself GordonFreeman claiming 1,953,721 records from Spain's Ministry of Foreign Affairs, including names, emails, dates of birth, nationalities, phone numbers, identity document data, postal addresses, internal IP addresses, user identifiers, and CSRF tokens. The Ministry flatly denies the breach, stating that neither headquarters nor embassies and consulates have been hacked. That denial versus claim standoff is unresolved, and it is a useful reminder that hacktivist volume claims in this theatre routinely outrun what can be verified.
Why It Matters
Personnel identity data is not the usual doxxing payload. Financial records and intellectual property have downstream monetary value; the true names, contact details, and service affiliations of serving intelligence officers have immediate operational value to a hostile service. They enable target packages, coercion and recruitment approaches, counterintelligence deconfliction of the adversary's own operations, and physical surveillance of officers and their families. If the claims are accurate even in part, the affected services face burned covers rather than a privacy incident.
The APTDesi interview gives an unintentionally clear picture of the intended effect. He describes the September 2025 disclosure as forcing affected officials to change email addresses, phone numbers, and devices, and prompting offers of counter-surveillance measures so they could move around safely. That is the point of the operation: even an exaggerated or partly fabricated leak imposes real remediation cost, degrades operational tempo, and produces the internal anxiety he is happy to advertise. Doxxing here is a cheap, deniable form of disruption whose effectiveness does not depend on the data being complete or wholly authentic.
The Spanish National Police warning in the Granada case makes the same point from the defensive side: such disclosures expose public officials to harassment, threats, extortion, and coordinated targeting campaigns. That is the concrete risk model regardless of which claim turns out to hold up.
The threat-actor picture also matters. NoName057(16) appears both in the hacktivists' own claims and in Spanish police casework, and the UK's NCSC has named NoName057(16), CARR, and Z-Pentest in an advisory on the risk these groups pose to Western critical national infrastructure. NCSC director of national resilience Jonathon Ellison cautioned that Russian-aligned hacktivist groups continue to target UK organisations and that technically simple denial-of-service attacks can still have significant impact. US officials have said CARR was working with or receiving instructions from Russian military intelligence (GRU). Groups previously filed under low-impact DDoS nuisance are now claiming, and in at least some cases attempting, intelligence-relevant data theft with a stated pipeline to Russian services.
The Attack Technique
There is no confirmed intrusion chain for the intelligence-personnel claims. What exists is the actor's own description and inference from other reporting.
APTDesi describes a human-enabled approach rather than a purely technical one: a network of informants who provide initial access, followed by incremental lateral movement from one "door" to the next using varied means and methods. That is a claim of insider-assisted access chained with pivoting, not exploitation of a named vulnerability. It is unverified.
StoryChase assesses that Spanish law enforcement systems, which interface with broader European security infrastructure, appear to have lacked sufficient segmentation to prevent lateral movement into intelligence agency networks, and that the ability to consolidate personnel records across multiple organisations suggests weak access controls or compromised credentials with broad privileges. That is analytical inference by a single OTHER-tier outlet, not a forensic finding, and should be read as a hypothesis.
For the adjacent Foreign Ministry claim, Roams reports that the cyberintelligence account Hackmanac attributed the alleged access to an IDOR (Insecure Direct Object Reference) flaw, where manipulating an identifier in an application request returns data that should be restricted, with no credential theft required. Roams explicitly states that neither the entry vector nor the true scope has been independently confirmed, and that there is no indication the attacker obtained administrative access.
The broader Spanish caseload points at the mundane failure modes that actually produce these datasets. Outpost24's analysis of the Endesa breach, published via Global Security Mag, examines compromised credentials and privileged access as the likely origin of a dataset advertised in January 2026 by a seller using the aliases "glock" and "spain" as covering more than 20 million individuals. Endesa confirmed on 11 January 2026 that it had detected unauthorised and illegitimate access to certain customer personal data, said passwords were not compromised, and reported no evidence of fraudulent use at disclosure time, while noting attackers accessed and likely exfiltrated identification data, contact details, national identity numbers, contractual information, and payment details including IBANs. No actor has been formally attributed. In the 23andMe case, Spain's AEPD fined the company 2.4 million euros (about 2.7 million dollars) and found that the absence of mandatory multifactor authentication was a major enabling factor in a credential stuffing attack, alongside the lack of per-IP limits on accessing, requesting, or downloading data. The AEPD decision covers more than 2,600 Spaniards out of 6.9 million people affected worldwide, and criticised the company's 12-day delay in notifying Spanish authorities.
What Organizations Should Do
- Treat personnel directories as a crown-jewel asset, not HR data. Apply the same segmentation, access logging, and need-to-know restriction you would apply to operational systems, and specifically prevent any single credential from being able to enumerate personnel records across multiple agencies or organisational boundaries.
- Enforce mandatory multifactor authentication and rate-limit bulk access. The AEPD decision against 23andMe named missing mandatory MFA and the absence of per-IP limits on access, requests, and downloads as core failings. Add per-account and per-IP thresholds on record retrieval and alert on enumeration patterns.
- Hunt for IDOR and broken object-level authorisation in any portal exposing personal records. The Foreign Ministry claim, whatever its ultimate accuracy, describes a class of flaw that requires no credentials and leaves few conventional intrusion artefacts. Test authorisation on every object reference, not just authentication at the front door.
- Build an officer-exposure response playbook in advance. Assume identity disclosure is the objective and pre-plan rapid rotation of emails, phone numbers, and devices, plus counter-surveillance and personal-security support, since the operational cost lands on individuals within hours of publication.
- Monitor for your own personnel data on leak platforms and cybercrime forums. Both the Granada case and the Endesa case surfaced through public posting or forum advertisement rather than internal detection, and the 23andMe breach reached executives only after data appeared for sale on Reddit.
- Treat insider and informant-enabled access as an in-scope vector. The actor's own account centres on human sources providing initial footholds, so pair technical controls with vetting, privileged-access review, and behavioural monitoring on staff who can reach personnel databases.
- Do not let notification lag. The AEPD called the need for immediate regulator notification "not trivial" and penalised a 12-day delay; for personnel-safety incidents, the window for protective action is shorter still.
Assessment and Confidence
Accounts differ in a way worth stating plainly. The 400+ intelligence officer exposure is, at this point, an attacker claim amplified by Russian state-aligned media, with no primary confirmation from Spanish authorities, NATO, or any CERT, and no independent verification of the dataset. The claim that the data was passed to Russian intelligence agencies rests entirely on the hackers' own assertion, reported by StoryChase, and serves their stated propaganda goal. Confidence in the specific figure and in the SBU, CIA, and MI6 attributions is low.
Confidence is considerably higher that pro-Russian actors are actively and successfully targeting Spanish official personnel data as a category, and that Spanish authorities regard the threat as serious. That rests on the two documented arrests reported by The Record and The Register, the seizure of equipment for forensic analysis, the NCSC advisory naming the same group ecosystem, and US assessments linking CARR to the GRU. Defenders should plan against the pattern, which is well evidenced, while withholding judgement on the headline number, which is not.
Sources: Pro-Russian Hackers Expose 400+ Spanish and Ukrainian Intelligence... | Spain arrests suspected hacker for publishing personal data of poli... | Spain fines 23andMe nearly $3 million for cybersecurity failings en... | Alleged pro-Russia hacktivist arrested in Palencia | Hackers Expose Spanish and Ukrainian Intelligence Personnel | 'Hacker' prorruso tras obtener datos de espías españoles: "La intel... | Un hacker asegura haber robado los datos de casi 2 millones de pers... | Computer Security Global Security Mag Online anti virus spywares jo...