The ransomware-as-a-service group Qilin claimed to have breached Spain's tax authority, Agencia Tributaria, and exfiltrated 60 gigabytes of sensitive data, listing the agency on its darkweb leak site. However, Spanish officials and a review of the leaked data confirmed that the information did not originate from the tax agency, and there was no evidence of a successful compromise. Authorities stated that the posted data samples were linked to a third-party business management firm and not to the tax agency itself.
Spanish state newswire and agency spokespeople categorically denied any connection between the Qilin leak and the tax authority, emphasizing that the extortion group's claims were unfounded. The incident highlights the growing trend of ransomware groups making false or exaggerated breach claims to pressure organizations and attract attention, underscoring the importance of thorough verification before responding to extortion attempts or publicizing alleged breaches.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
Initial story creation
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.