Pro-Russian hacker groups PalachPro, APTDesi and NoName057 have claimed that they breached databases belonging to Spanish law-enforcement and security agencies and exposed information on more than 400 intelligence personnel. The claims were reported by media on Aug. 2, 2026, but Spanish authorities have not issued an official response.
The groups have not publicly provided independently verified evidence that the databases were compromised. Their statements also have not been confirmed by Spanish officials or other authorities.
Claims about intelligence personnel
According to the hackers’ account, the material allegedly includes the identities of officers from the Spanish army and agents of security services who cooperate with the U.S. Central Intelligence Agency, Britain’s Secret Intelligence Service, known as MI6, and Ukraine’s Security Service.
The claims refer to personnel from Spanish and Ukrainian intelligence structures. The groups also said that the information they obtained had been passed to Russian intelligence services. The statement was circulated through a Telegram channel linked to the reporting: the published account of the alleged breach.
No details have been released publicly about the alleged databases, the method of access, the period during which the operation took place or the number of records that may have been authentic. It is also not clear whether the claimed disclosure involved current personnel, former employees or other individuals connected to the agencies.
Earlier claims involving European systems
The allegations follow a separate operation claimed by NoName057 and hackers from PalachPro in June 2026. The groups called that operation Broken Byte and said they had compromised more than 50,000 surveillance cameras in European Union member states.
The available account does not establish whether the alleged access to Spanish security databases was connected to Broken Byte. It does, however, place the latest claim in a sequence of operations publicly attributed to the same or related groups.
NoName057 has previously been associated with cyberattacks against Spanish targets. In 2025, Spanish police accused Enrique Arias Gil, a 37-year-old former professor at a university in Madrid, of sabotage, cyberterrorism in the European Union and cooperation with NoName057. Spanish authorities have linked the group to about 500 cyberattacks against Spain.
Following the accusations, Arias Gil was added to Europol’s wanted list. He is reported to be in Russia, where he travelled in 2024 to study the Russian language.
The case of Enrique Arias Gil
While in Russia, Arias Gil operated a Telegram channel that published lists of potential targets for cyberattacks. The targets reportedly included Spanish seaports and government institutions.
He has also been accused of collecting classified information about critical infrastructure in Spain and members of the country’s security services. The publicly described case does not establish whether he had access to the databases mentioned in the latest hackers’ claims.
The accusations against Arias Gil remain separate from the unverified statements by PalachPro, APTDesi and NoName057. Neither Spanish authorities nor Europol has been cited as confirming that the three groups obtained the identities of intelligence personnel or transferred the material to Russian services.
Cyberattacks and data disclosures attributed to pro-Russian groups have been reported against government, security and infrastructure targets in European countries. In this case, the alleged victims include institutions in a NATO member state, while the reported claims also refer to cooperation involving U.S., British and Ukrainian services.
The source material does not provide an official assessment of the alleged incident, the condition of the affected systems or any operational measures taken by Spain. Confirmation of the breach, the authenticity of the data and the scope of any compromise would require statements from the relevant Spanish agencies or an independent technical investigation.
Spanish authorities had not publicly commented on the reported claims at the time of publication.