Spain: Nearly 1,000 Police and Military Personnel Targeted by Sensitive Data Leak
A significant leak of sensitive data targeting Spanish security forces is under investigation. A file of nearly 500 pages, containing personal information on several hundred police officers, civil guards, and military personnel, has reportedly been disseminated online. The professional association Justicia Guardia Civil (Jucil) has approached the Audiencia Nacional to shed light on the origin and those responsible for this leak.
A File Containing Sensitive Personal Data
The document at the center of the case reportedly compiles personal information on nearly 1,000 members of the Spanish security forces. Among the data mentioned are the names and surnames of the agents, their photographs, their phone numbers, as well as their identifiers on Telegram.
Some information from personal directories has also allegedly been included in the file. The document, which spans approximately 500 pages, thus presents a particularly detailed set of information that could facilitate the identification and contact of the individuals concerned.
Its header, written in Russian, allegedly states "List of Spanish Security Forces." The specialized press has mentioned a possible involvement of NoName057, a pro-Russian hacker collective known for its operations against Western targets. However, this attribution has not yet been officially confirmed by Spanish authorities.
An Investigation to Determine the Source of the Leak
In light of the seriousness of the facts, the National Police and the Centro Nacional de Inteligencia (CNI) have initiated investigations to determine how the information was obtained and for what purpose it was made public.
Jucil particularly wants investigators to establish whether the data resulted from a cyber intrusion or from unauthorized access to phones, private accounts, institutional systems, or protected databases.
In its approach to the Audiencia Nacional, the association requests that those involved in the various stages of the operation be identified: extraction of information, compilation of the file, and dissemination of the content online.
The organization also demands precautionary measures to limit, as much as possible, access to the document and to prevent its spread. It emphasizes the need to preserve digital traces that could allow investigators to reconstruct the file's path and identify the channels used for its dissemination, particularly on Telegram.
An Increased Risk for Agents and Their Families
Beyond the violation of personal data, Jucil warns of the potential consequences of their aggregation in a single document. The combination of photographs, phone coordinates, and digital identifiers could facilitate direct contact with the agents and, in some cases, allow for cross-referencing information related to their personal environment.
Risks mentioned include phishing attempts, social engineering, identity theft, intimidation campaigns, or even targeting agents in malicious operations.
"The security and privacy of our civil guard colleagues and their families cannot be used as a bargaining chip or exposed with impunity online," stated Jucil's General Secretary, Ángel Lezcano.
The association has announced the mobilization of its legal services to assist members who may be affected. It encourages them to keep elements documenting the dissemination of their information and to remain particularly vigilant regarding unusual calls, messages, or solicitations.
A Legal Procedure Still in Its Early Stages
The complaint filed by Jucil must now be examined by the Audiencia Nacional. It will be up to the jurisdiction to rule on its admissibility and on the judicial follow-up to be given to the case.
At this stage, several questions remain unanswered. Authorities have not publicly established the exact origin of the data, the method used to obtain it, nor the definitive extent of the breach. The identity of the individual or individuals responsible for the dissemination has also not been officially established.
This case nonetheless illustrates a central issue for security institutions: the protection of personal data of agents is no longer limited to professional IT systems. Phones, private accounts, and traces left on digital platforms can also constitute points of exposure that may be exploited by malicious actors.
-
09:47
-
09:44
-
09:32
-
09:15
-
22:00
-
21:41
-
21:21
-
21:05
-
20:45
-
20:30
-
20:15
-
19:47
-
19:32
-
19:15
-
19:00
-
18:42
-
18:25
-
18:15
-
18:10
-
17:47
-
17:32
-
17:15
-
16:50
-
16:32
-
16:16
-
15:56
-
15:40
-
15:20
-
15:05
-
14:45
-
14:30
-
14:15
-
14:00
-
13:42
-
13:25
-
13:10
-
12:47
-
12:31
-
12:15
-
12:00
-
11:42
-
11:25
-
11:11
-
10:47
-
10:32
-
10:15
-
10:09
-
10:00