Hackers claim data breach that could expose millions of Spanish pensioners
Records are being offered for sale online.

- A hacker claims to have stolen over 3 million Spanish pensioner records from Spain’s Social Security agency.
- Cybernews researchers found samples with DNI numbers, names, birth dates, partial IBANs, addresses, and contact details.
- The attacker says they tried to extort the agency before offering the alleged breach data for sale online.
- The data could help scammers create convincing phishing attacks, putting older users at higher risk of digital fraud.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Millions of Spanish pensioners could be at risk of phishing attacks, after a hacker claimed to have stolen highly sensitive data from Spain's national Social Security agency.
A post appeared on an infamous hacker forum claiming that over 3 million records belonging to Spain’s pensioners have been stolen.
The alleged attacker claims that the data originated from Instituto Nacional de la Seguridad Social (INSS), an official Spanish government agency that manages and pays out state economic benefits, such as pensions, sick leave, and maternity or paternity allowances.
A threat actor has posted several data samples to back up their claims and find potential buyers. Such datasets offer a bargain for scammers. By exploiting large-scale datasets with private user information, scammers can craft highly convincing phishing attacks.
Older users can be especially vulnerable to digital fraud and could press malicious links or provide other sensitive details, convinced that the email is legitimate.
Cybernews researchers, who investigated the data sample, found over 100 sample records that include highly sensitive Spanish citizens’ data, including:
- DNI numbers
- Full names
- Dates of birth
- Partial IBANs
- Home addresses
- Contact information
Did the Spanish government refuse to pay?
The attacker claims in the post that they contacted the organizations and demanded a ransom payment not to leak the stolen data.
“Not receiving further response, I came here to sell this breach from Instituto Nacional de la Seguridad Social, which includes ALL pensioners in Spain,” the attacker wrote.
The attacker also said that the dataset on sale is in JSON format. However, they claim to have more files that are in PDF and image formats.
The tool that the attacker claims they used to exfiltrate data is TerciosRAT. It is a type of remote access trojan (RAT). Unlike ransomware, which primarily encrypts files, a RAT is designed to secretly give attackers persistent remote control over an infected device.
While the data appears to belong to real people, rather than being fabricated, the Cybernews research team was not able to confirm how recent the data is.
Cybernews has reached out to INSS for comment. We will update this article once a response is received.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.