The NoName057(16) network published sensitive information after targeting Spain, raising the risk of intimidation, blackmail and further cyber operations against police and military personnel.
A Russian-linked hacking network has obtained and published confidential data belonging to nearly 1,000 Spanish police officers, Civil Guard members and military personnel, according to a document released by NoName057(16) and reported by El País on 17 August 2026.
The material includes officers’ names, photographs, telephone numbers, email addresses, home addresses and contacts from their address books. Spain’s General Information Commissariat (CGI), through its cyber-threat division, is investigating how NoName057(16) gained access to the information.
A direct threat to personnel and their families
The operation is the latest cyberattack attributed to NoName057(16) against Spain since the government of Pedro Sánchez expressed support for Ukraine in Russia’s war. The group has targeted public institutions and critical infrastructure in European Union and Nato countries that back Kyiv, using distributed denial-of-service attacks, data theft and disinformation campaigns.
The publication of personal information turns a cyber intrusion into a direct security risk. Home addresses and telephone numbers can be used for targeted threats, harassment, blackmail and psychological pressure against officers and their families. The exposure also signals that information gathered during an attack can be repurposed beyond the original breach.
Details about members of the police, Civil Guard and armed forces may also support phishing and social-engineering attempts, in which attackers exploit personal relationships or professional trust. The material could be used to seek access to official systems, pressure individuals, attempt recruitment or identify further targets.
From data theft to psychological warfare
NoName057(16) emerged in March 2022, shortly after Russia’s full-scale invasion of Ukraine. Since then, it has operated as part of the Kremlin’s wider hybrid campaign against European states, combining disruptive cyberattacks with the collection and dissemination of information.
Publishing stolen data through media outlets and pro-Russian information channels allows such attacks to produce effects beyond the systems originally compromised. The exposure is intended to deepen the sense that public authorities cannot protect their own personnel, demonstrate the reach of Russian-linked hacker groups and undermine confidence in European governments.
That makes the Spanish incident more than a conventional cybercrime case. The immediate victims are individual security personnel, but the wider target is the confidence of the state and the public. By placing officials and their families under potential pressure, the operation seeks to make support for Ukraine appear to carry an additional domestic cost and to increase pressure on governments providing that support.
International action weakened the network, but did not end it
The attack also highlights the limits of temporary disruption. On 15 July 2025, law-enforcement agencies from 12 European countries carried out Operation Eastwood against NoName057(16). Authorities searched premises in seven countries, arrested suspects in France, Spain and Poland, issued arrest warrants for seven people and disconnected more than 100 servers used to host the group’s infrastructure.
The operation temporarily dismantled the botnet used for attacks around the world, but the network’s subsequent activity shows that disrupting infrastructure is not the same as eliminating the threat. Among those suspected of links to the group is Enrique Arias Gil, a Spanish IT specialist known by the alias “El Desinformador ruso”. He is accused of spying for Russia and has been granted political asylum there.
The stolen Spanish data could therefore remain valuable long after the initial breach. Personal information can be reused in later cyber operations, targeted influence efforts or attempts to penetrate security structures. The consequences are not confined to the moment of publication: the information may provide a durable pool of targets for hostile activity.
Spain’s investigation will now need to establish the route by which the information was accessed and how widely it has been distributed. For European governments, the incident reinforces the need for sustained co-operation between police forces, intelligence services and cyber-security authorities. Operation Eastwood demonstrated that joint action can significantly weaken Russian hacker infrastructure; preventing its recovery requires that co-ordination to continue.
How should European governments balance the disruption of hacker networks with the long-term protection of personnel whose personal data has already been exposed?