Hackers rusos exponen datos de cientos de policías y militares españoles

Aproximadamente mil miembros de las fuerzas de seguridad españolas han tenido sus datos personales, fotografías y números de teléfono expuestos públicamente, comprometiendo su seguridad personal y la de sus contactos.
Viven sabiendo que sus datos están en manos de actores hostiles
La exposición de datos de mil miembros de las fuerzas de seguridad crea una vulnerabilidad permanente para los afectados.
Mark

¿Por qué exponen los nombres de mil personas de una vez? ¿No es más efectivo mantenerlo en secreto?

Mimi

Eso es lo que los investigadores no terminan de resolver. Podría ser un acto de intimidación puro—demostrar que pueden llegar a cualquiera. O podría ser un catálogo de objetivos para futuras operaciones de reclutamiento o chantaje.

Mark

¿Y este Enrique Arias Gil? ¿Cómo termina un profesor madrileño trabajando para los rusos?

Mimi

No sabemos exactamente cuándo o cómo se radicalizó. Pero lleva años recopilando información sobre infraestructuras críticas españolas. Ahora está en Moscú, protegido por el Estado ruso. Es difícil volver de eso.

Mark

¿Qué tan profundo es el control ruso sobre estos grupos de hackers?

Mimi

Más profundo de lo que parecía. Descubrieron que todos estos colectivos supuestamente independientes responden a una sola agencia estatal rusa. No son rebeldes. Son brazos del Estado.

Mark

¿Y las operaciones policiales? ¿Funcionaron?

Mimi

Bloquearon cientos de servidores, recuperaron datos, hicieron arrestos. Pero el daño ya estaba hecho. Los nombres ya circulaban. Lo que ganaron fue inteligencia sobre cómo funciona la red.

Mark

¿Qué pasa ahora con esos mil policías y militares?

Mimi

Viven sabiendo que sus datos están en manos de actores hostiles. Sus números de teléfono, sus contactos, sus fotografías. Es un riesgo permanente.

  • Documento de 499 páginas con nombres, fotografías y números de teléfono de aproximadamente mil miembros de fuerzas de seguridad españolas
  • Enrique Arias Gil, profesor madrileño de 38 años, identificado como presunto filtrador, actualmente en Rusia bajo protección estatal
  • Operación internacional en 2025 bloqueó más de 100 servidores de NoName057 en 12 países; en España se bloquearon 42 servidores
  • Arresto de un italiano de 34 años en Palencia en marzo de 2026, acusado de coordinar ataques en España

El ataque reveló identidades, contactos y datos personales de policías nacionales, guardias civiles, militares e investigadores privados en un documento titulado en ruso. Los investigadores sospechan que el objetivo fue sembrar miedo entre los agentes de seguridad o compilar una lista de posibles objetivos de captación futura.

Un ciberataque atribuido al grupo NoName057 ha expuesto datos de aproximadamente mil miembros de las Fuerzas y Cuerpos de Seguridad del Estado español, incluyendo nombres, fotografías y números de teléfono en un documento de 500 páginas.

A 499-page document circulating online contains the names, photographs, and phone numbers of roughly a thousand Spanish police officers, Civil Guard members, military personnel, and at least one private investigator. The file carries a header in Russian reading "List of Spanish security forces," and intelligence services have attributed the breach to NoName057, a sprawling hacktivist collective aligned with Russian interests. Though the group operates across multiple nationalities—including Spanish and Italian members—its leadership and coordination appear rooted in Moscow's strategic objectives.

The exposed individuals span a wide range of roles and ranks. Among them are a sub-inspector assigned to the Special Operations Security Groups, officers working in citizen services units, soldiers from the Army, Civil Guard agents, security escorts, and a private investigator. Many of the profiles belong to recently graduated civil servants, which has led investigators to consider two competing theories about the breach's intent. The first suggests the attack was indiscriminate, designed primarily to instill fear among security personnel. The second proposes the list functions as a recruitment roster—potential targets for future radicalization or coercion by hostile actors.

NoName057 itself emerged in March 2022, in the immediate aftermath of Russia's invasion of Ukraine. The group specializes in distributed denial-of-service attacks against NATO members and Ukraine's allies, including Spanish government agencies and critical infrastructure. In previous campaigns, they have targeted websites of the Interior Ministry and the national railway operator during electoral periods. Their stated mission aligns with Russian state interests, though the group maintains a veneer of independent hacktivist identity.

Behind the data compilation stands a figure Spanish authorities have been pursuing for over a year. Enrique Arias Gil, a 38-year-old Madrid-based teacher, is wanted by Spain's National Court on charges of computer damage with terrorist intent, apology for terrorism, and membership in a criminal organization. Intelligence sources identify him as the user known as "desinformador ruso"—the Russian disinformer—and credit him with systematizing the collection of sensitive information about Spain's critical infrastructure and security personnel. Arias Gil currently resides in Russia under state protection, according to police investigations, and appears on Europol's most-wanted list.

The Spanish National Police's Information General Commissariat and the National Intelligence Center have spent months mapping the architecture of pro-Russian hacking groups operating against European and NATO targets. Their work has revealed that these organizations, long assumed to operate as autonomous collectives, actually answer to a single Russian state entity: the Center for the Protection of Youth and Childhood. This body was created and funded directly by Vladimir Putin's government.

Two major operations have brought this structure into focus. The first occurred last year, when the Information General Commissariat coordinated a complex international operation involving ten European police forces and the United States. The effort successfully disrupted NoName057's infrastructure across twelve countries, blocking more than one hundred servers. In Spain alone, authorities blocked access to forty-two servers and recovered data from twenty-five others, deleting information from eight additional systems. Police conducted three raids in Madrid, one in Barcelona, and another in Zaragoza, and interrogated five individuals.

The second breakthrough came in March of this year, when Spanish police arrested a 34-year-old Italian national in Palencia. Authorities accuse him of coordinating the group's attacks within Spain. These operations suggest that while NoName057 maintains a distributed structure, its command and control ultimately traces back to Moscow—and that Spain's security apparatus is beginning to map those connections with precision.

Los investigadores manejan dos tesis: que el ataque no fuese quirurgico y buscase más sembrar miedo entre los policías, o que se trate de una lista de objetivos a los que tratar de captar en el futuro
— Fuentes de investigación citadas en el reportaje
Está acusado de daños informáticos con fines terroristas, apología del terrorismo y pertenencia a una organización criminal
— Cargos contra Enrique Arias Gil ante la Audiencia Nacional
Quer a matéria completa? Leia o original em La Razón ↗
Fale Conosco FAQ