# Spanish Police Arrest Doxer Behind Massive Government Data Leak Targeting Critical State Agencies


Spain's National Police have arrested an individual responsible for orchestrating a large-scale doxing operation that exposed sensitive personal information of government employees across multiple critical state institutions. The arrest on May 27 marks a significant law enforcement response to what authorities described as a threat to national security, following the systematic leak of data from Spain's most sensitive agencies.


The investigation, overseen by Madrid Investigative Court No. 22, culminated in the raid of the suspect's residence and the seizure of computers and electronic devices containing potential forensic evidence. Spanish authorities have indicated that additional arrests may follow as they continue examining the seized equipment for evidence of potential collaborators.


## The Scope of the Breach


The leaked data originated from some of Spain's most critical government entities, creating immediate and substantial security risks:


  • State Attorney General's Office — the nation's top prosecutorial authority
  • INCIBE (National Cybersecurity Institute) — Spain's primary cybersecurity defense organization
  • National Police — Spanish law enforcement's main federal agency
  • Civil Guard — Spain's militarized police force
  • National Security Council — the highest-level government security coordination body

  • The breadth and sensitivity of the affected agencies underscore the severity of the incident. These organizations are responsible for national security, law enforcement operations, and critical infrastructure protection. The exposure of their employees' personal information creates direct operational risks, from harassment and targeting to potential blackmail or intimidation campaigns.


    ## How the Data Was Compiled


    According to statements from INCIBE in February, when the agency first acknowledged the doxing campaign, the leak did not result from direct breaches of government systems. Instead, the threat group responsible—'Police-ESP-Doxed'—appears to have employed a more sophisticated approach: aggregating and correlating publicly available information with data from older breaches and credential dumps.


    The methodology likely involved:


    | Data Source | Method | Risk Level |

    |---|---|---|

    | Older breaches | Purchasing or accessing leaked databases | High |

    | Credential dumps | Dark web purchases or leaked repositories | High |

    | OSINT (Open Source Intelligence) | Public records, social media, professional networks | Medium |

    | Data correlation | Cross-referencing multiple sources to build profiles | High |


    This approach is particularly insidious because it doesn't require compromising secure government systems. Instead, threat actors can achieve similar results by combining publicly available information with data that has already been exposed through previous security incidents. The technique allows doxers to create comprehensive, curated profiles of targets without leaving detectable traces within the victim organizations' own infrastructure.


    Notably, some of the leaked records contained outdated information, including names of former INCIBE employees who had left the organization years earlier. This detail suggests the threat group was working with stale data, potentially sourced from multiple breaches spanning years.


    ## The Public Dissemination


    The initial leak of government employee data was published by the 'Police-ESP-Doxed' group on BreachForum, a notorious dark web marketplace for stolen data and criminal services. Later, in March 2026, a follow-up doxing operation targeted Spanish judges and prosecutors specifically, with hundreds of sensitive records published on Doxbin—another platform specializing in doxed personal information.


    The March leak included particularly sensitive identifiers:


  • Full names
  • DNI numbers (Spain's national identification numbers)
  • Personal mobile phone numbers
  • Professional email addresses

  • The publication of judicial officers' information represents an escalation, as judges and prosecutors are high-value targets for criminal organizations and extremist groups seeking to intimidate or influence legal proceedings.


    ## Investigation and Ongoing Enforcement


    The Spanish National Police emphasized the speed and priority with which they conducted the investigation. Upon detecting the mass dissemination of government employee data, authorities moved quickly to identify, locate, and apprehend the responsible party. The recovery of computers and electronic devices from the suspect's residence will likely yield forensic evidence about the scope of the operation, the involvement of other participants, and potential future targets.


    Spanish authorities have not publicly disclosed whether the arrested individual was solely responsible for both the initial government employee leak and the subsequent judicial officer doxing, or whether additional participants are involved. The ongoing forensic examination suggests investigators are pursuing leads into potential collaborators.


    ## HackWire Analysis


    This arrest highlights a critical vulnerability in how modern governments manage employee information. While cybersecurity investments typically focus on perimeter defense and intrusion detection, the doxing vector—aggregating and weaponizing publicly scattered information—bypasses these protections entirely. Spain's INCIBE correctly noted that no direct breach of government systems occurred; instead, threat actors exploited a more fundamental problem: the inability to control how employee information disperses and correlates across the public internet.


    The pattern is instructive. As organizations struggle to defend against sophisticated intrusions, persistent threat actors have increasingly shifted to lower-risk, higher-reward doxing campaigns that weaponize OSINT and old breaches. This reflects a rational economic calculation: why risk detection and prosecution by hacking a hardened network when you can aggregate the same intelligence from dozens of public and semi-public sources?


    The timing and scope suggest this wasn't random harassment. Targeting state prosecutors, judges, and cybersecurity agency staff indicates either political motivation or organized crime seeking leverage. The careful coordination—leaking to BreachForum, later escalating to Doxbin—shows operational sophistication and suggests the perpetrator(s) understood the escalating pressure this would place on Spanish authorities.


    For defenders, the lesson is stark: employee data hygiene and OSINT monitoring are now as critical as network defense. Organizations can no longer assume their employees' personal information will remain private. Government agencies, law firms, financial institutions, and critical infrastructure operators should implement systematic OSINT monitoring, enforce strict policies on what employee information appears in public directories, and educate staff on the doxing risks they face by virtue of their position.


    The Spanish government's rapid response and arrest are commendable, but the underlying vulnerability—the persistence of aggregated personal data in public and semi-public spaces—remains unresolved.


    — HackWire Editorial


    ## Implications for Government Employees and Operations


    The exposure of personal information for government employees creates several cascading risks:


    Operational Security Threats: Personnel at security agencies and law enforcement may become targets for surveillance, harassment, or recruitment by criminal organizations or hostile nation-states seeking intelligence or leverage.


    Physical Security Risks: Published phone numbers and addresses enable targeted harassment or worse. The publication of judges' and prosecutors' personal information is particularly concerning, as it enables intimidation of the judiciary.


    Insider Threat Potential: Bad actors with this information can attempt to recruit government employees, using the data as evidence of successful intelligence gathering to demonstrate capability and seriousness.


    ## International Context and Broader Trends


    Doxing campaigns targeting government officials and agencies have become increasingly common globally. These operations typically serve multiple purposes: intelligence gathering, reputational damage, operational disruption, and political messaging. The Spanish incident fits into a troubling pattern where both state-sponsored actors and criminal organizations weaponize personal data as a strategic tool.


    ## Recommendations


    For Government Agencies:

  • Implement continuous OSINT monitoring to identify leaked employee information
  • Develop incident response protocols specifically for doxing and mass personal data exposure
  • Educate employees on operational security practices and the risks of oversharing information online
  • Require periodic reviews of what personal information is publicly discoverable about staff

  • For All Organizations:

  • Audit what employee information is exposed through public directories, social media, and professional networks
  • Establish policies limiting what information appears in public-facing systems
  • Monitor dark web forums and doxing platforms for mentions of your organization or employees
  • Develop rapid response protocols for when employee data is discovered in leaks

  • For Individuals in Sensitive Positions:

  • Minimize personal information available on social media and professional networks
  • Use privacy settings aggressively on all platforms
  • Consider using variations of names or different contact methods for personal and professional spheres
  • Monitor dark web forums for mentions of your name or identifying information

  • ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)