No security breach in the computer systems of the Ministries of the Interior and Defense nor a sophisticated cyberattack to steal inaccessible sensitive information. The investigation by the Cyber Threat Unit of the General Information Police Commission (CGI) of the National Police into the recent dissemination of photographs and personal data of nearly 2,000 police officers, civil guards, military personnel, and agents of the National Intelligence Center (CNI) has confirmed that this disclosure of personal data was actually caused by the indiscretion of those affected, who in the vast majority of cases had made public their status as members of the security forces on their personal profiles on social networks and in publicly accessible chats on instant messaging applications.
Read more The largest wave pool in Europe brings discord to a district of Madrid: «It is nonsense»
The police investigation has also identified the author of the dissemination of these thousands of data: it is Enrique Arias Gil, a 38-year-old Spanish professor who has been wanted since 2025 for his links to the hacker group NoName057(16), associated with Vladimir Putin’s regime. However, investigators frame the publication of this data not so much as part of the network’s strategy, but as a desire for revenge that Arias has against the Police since last year when a judge issued an international arrest warrant against him for his involvement in NoName057’s cyberattacks in Spain. Arias announced this revenge on channels sympathetic to the group and named it ironically Operation Mortadelo, referring to the clumsy secret agent from the comic. So far, however, his revenge has had rather modest results, according to sources close to the investigation.
The professor ―who in 2021 participated in a La2 program as an analyst and expert on extremism― began the leak shortly after becoming a fugitive with a steady drip of names and photographs of alleged members of the security forces through a Telegram instant messaging app chat aimed at Spanish speakers that he administered and used to promote NoName057’s cyberattacks and support pro-Russian narratives in its war with Ukraine. According to the investigation, most of the information was obtained from the agents’ own profiles on the social network Instagram and an open chat precisely on Telegram where members of the security forces contact each other to look for rental apartments when they change assignments. All this information, which he gradually uploaded, was finally compiled into a 499-page document that he disseminated on July 27 through the same channel. Shortly after, he closed the chat, which is now inaccessible.
The report prepared by Arias, accessed by EL PAÍS, is headed with the phrase in Russian “List of the Spanish security forces” and then immediately shows the photograph of a uniformed military man supposedly used by him on his profile on some social network, accompanied by his name, place of residence, mobile phone, email address, and four phone numbers included in his agenda. The second affected is a female member of the Army, with two images and the supposed address of her home in Pamplona, among other data. The third is an “active escort” who in one of the two images appears holding an assault rifle. The fourth, a private detective… Numerous files mention precisely Telegram application metadata (identification codes and username), which, according to investigators, confirms that a significant part of the information disseminated came from that Russian-origin platform.
In fact, the document seems limited to a succession of personal data of each affected person, placed one after another without any systematization, mostly in Spanish, but also with numerous words and notes in Russian. Some are explicitly identified as military, police, or civil guards, even with reference to their units, but others do not explicitly mention which police force they belong to. Sources close to the investigation highlight that there is a lot of old data; some are incorrect and sometimes a person is mistakenly attributed to the National Police when they are actually a civil guard, and vice versa. “Many of the affected are young agents who have been in the security forces for a short time, but precisely because of their youth, they are more prone to disclose their status as agents on their social networks, often wearing the uniform,” the sources close to the investigation point out.
Read more The invented accent of Snow White: past and future of neutral Spanish

Regarding Arias, investigators point out that “he is by no means a computer expert and to prepare the list he only used information easily extractable from freely accessible places.” “He is far from being a hacker,” they add. In this sense, they believe that the Spanish professor ―who claims to have found protection from Moscow authorities and is about to obtain Russian nationality― what he has tried with this dissemination is to gain prestige within the pro-Russian cyberactivist network. In fact, NoName057’s main cybercriminal activity is very different from disseminating personal data of police officers. Specifically, it coordinates like-minded cyberactivists (estimated to be more than 4,000) to launch coordinated Distributed Denial of Service (DDoS) cyberattacks. That is, the massive sending of traffic to a website with the aim of collapsing it and making it inaccessible to other internet users. To carry them out, this group has developed its own software, named DDoSia. These attacks, beyond the reputational damage caused by revealing a website’s vulnerability, are not especially serious, according to experts. Usually, affected sites are operational again the same day.
In Spain, this group has launched more than 500 waves of cyberattacks since its creation in 2022 due to the Government’s support for Ukraine. The first, on October 14 of that year, targeted the Ministry of Defense’s website. Many of them have been linked to specific events. Thus, on July 23, 2023, the day of the last general elections, it tried to take down the Ministry of the Interior’s website. It did not succeed, although it caused occasional problems for three hours that afternoon. It also unsuccessfully tried to create a website identical to the Interior Ministry’s to impersonate it (the so-called mirror pages). “We don’t care if the right or the left comes to power in this country today [on 23-J]: both sides adhere to a pro-European position,” the group stated then in a note in English claiming these attacks. That day, the targets also included the websites of the Moncloa Palace, the National Statistics Institute (INE), Renfe, the Central Electoral Board, the Royal House, and the Madrid Arbitration Court, among others.
Noname057 suffered a major police blow in July 2025, when a joint large-scale police operation involving police from 10 European security forces, including the Spanish National Police, and the United States, supported by authorities from seven other states, dismantled much of its infrastructure. The operation named Eastwood severely hit the group by blocking more than 100 computer servers it used. In Spain, the National Police, in collaboration with the National Cryptologic Center (CCN) and the CNI, disabled access to 42. The blow was so significant that NoName057 took eight days to act again, a period considered “very long” in cybercrime by police experts. After that blow, Arias was placed on Europol’s most wanted list.
Read more Qusra houses surrounded by Israeli settlers and soldiers: «I feel like I’m in a prison»