N4t0x SpainData Leak: Massive Data Breach of Spanish Politicians & Police
Hacker N4t0x uses SpainData tool to leak personal data of Spanish politicians, police, and intelligence officers, exposing families and raising privacy risks.
Massive Data Leak of Spanish Politicians and Security Forces
A threat actor going by the alias N4t0x has leaked a dataset allegedly containing personal data of Spanish politicians, law enforcement officials, intelligence officers, and their families.
The attacker claims to have used a tool called SpainData, which allegedly provides real-time access to national ID numbers (DNI/NIF), phone numbers, addresses, emails, dates of birth, and familial links across the entire Spanish population.

Scope of the Leak
N4t0x claims to have access to "100% of the Spanish population" and has made this information available for free. The SpainData tool allegedly allows real-time queries on virtually all Spanish citizens.
Security Risks
This leak poses serious problems:
• Compromise of intelligence agents and CNI operations
• Exposure of law enforcement to possible retaliation
• Vulnerability of politicians to blackmail or extortion
• Risk to family members who have no connection to public life
Attacker's Motivations
N4t0x justifies their actions as a protest against political corruption and lack of transparency, although this does not legitimize the illegal leak of personal data.
Implications
This incident highlights:
• Critical vulnerabilities in government systems
• Urgent need to improve national cybersecurity
• Importance of protecting sensitive data of public officials
Recommendations
For those affected:
• Monitor suspicious activity in personal accounts
• Change passwords and access credentials
• Report anomalous activities to authorities
This leak underscores the urgent need to strengthen national cybersecurity infrastructure to protect both public servants and citizens.
Darkeye Research Team
SamuelTracking ransomware crews, breach disclosures and the tooling that matters — field notes from the Darkeye desk.
Intel briefing
Get breach reports before they trend
Ransomware intel and breach disclosures in your inbox. Signal only, no noise.
Read next //
Emerging Ransomware Group: Kryptos
Kryptos ransomware group debuts on Oct 8, 2025, launching coordinated attacks across the US, Australia, and Canada targeting key professional sectors.
Keep investigating //
Discussion (0)
Sign in to join the discussion
Share your take with the Darkeye community.
No comments yet. Be the first to weigh in.