Spain's national weather agency lands on a leak site

Published

Spain's national weather service has turned up on a ransomware gang's extortion site. On 11 September a crew calling itself Panzer added the Agencia Estatal de Meteorología (AEMET) to the victim list on its Tor site. AEMET is the state agency that issues Spain's official forecasts and its severe weather warnings, and it reports to the Ministry for the Ecological Transition and the Demographic Challenge.

AEMET has not commented, and nothing in the listing suggests forecasts or warnings have been interrupted.

What makes the post worth attention is the company it keeps. Panzer is about five weeks old and has spent most of them working through government bodies.

A five-week-old crew that collects public bodies

Panzer's leak site first appeared in August 2026, and WatchGuard's ransomware tracker lists it as an active, emerging ransomware-as-a-service operation running double extortion, meaning it steals data as well as encrypting it, and reachable through the Tox messenger. WatchGuard also tags the group a data broker. That label is worth pausing on: a data broker sells material it did not necessarily steal itself.

In IntelFusions incident records Panzer has claimed 24 organizations since 5 August. Five are government bodies, in five different countries: the regional government of Castilla-La Mancha in Spain on 17 August, the Government of Vojvodina in Serbia on 24 August, Portugal's Directorate-General for Education on 28 August, an Indonesian regional communications and IT office on 3 September, and now AEMET. The rest are ordinary mid-market targets, from a Thai oil products firm to a German university campus. Panzer's profile tracks the full list.

AEMET is the second Spanish public body Panzer has named in under a month, and its first national agency. It is not the first new crew this summer to start in Spain either: Global Secret Group debuted in July with a Spanish cloud host among 28 claims.

Why a forecaster is a tempting name to post

A national forecaster holds little of the payment data that makes a retailer profitable to extort. What it has is visibility. AEMET's warnings reach the public, aviation and maritime operators and the emergency services, so an interruption would be noticed within hours. For a crew still building a reputation, a recognisable state agency is worth something as a headline whether or not anyone pays. Public sector files carry real exposure too: a breach at Latvia's road safety agency in August exposed records on 1.2 million people.

A listing is a claim, not a confirmed breach

Everything on a leak site is written by the people who say they did it. The listing in our records carries no sample, no file count and no ransom demand, and the crew's own onion address, pnzruro7syvwvefx5mpo2fhzi4jftgquynsqf3vy5x3no57yp2iz4nyd[.]onion, is the only place the claim appears. The data broker label is why that matters here. A post can repackage material taken from somewhere else, or lifted from an older incident, and still go up as a fresh conquest.

Verify the sample, then notify CCN-CERT

No CVE is attached to this and no account of how anyone got in has been published, so there is nothing to patch on the strength of the post. For a Spanish public body the next steps are procedural: establish whether anything was actually published, check any sample against your own records before treating it as genuine, and notify CCN-CERT, which handles public sector incidents under the National Security Framework, rather than negotiating quietly. Spain rates as a high-targeting country in our profile, with INCIBE-CERT covering business and citizen reporting and NIS2 transposition tightening notification duties this year.

New brands arrive on the leak sites every few weeks and most are gone before anyone profiles them. The ones worth watching pick their targets rather than take whatever an affiliate drags in, and five government bodies in five weeks looks a lot like picking.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions