Spain’s Guardia Civil arrested four alleged members of the hacktivist group Anonymous Fénix for suspected distributed denial-of-service (DDoS) attacks against government ministries, political parties, and other public institutions. Authorities said the group emerged as an Anonymous offshoot in 2023 and used X and Telegram to publicize its activity and recruit participants, with operations intensifying after the 2024 DANA floods, when the group blamed public authorities for the disaster and claimed responsibility for attacks on public administration websites.
Investigators previously identified the group’s leadership—described as an administrator and a moderator—who were arrested in May 2025, and said evidence from that phase led to two additional suspects characterized as among the most active members, detained in Ibiza and Móstoles (Madrid). Under court order, law enforcement also seized control of the group’s online presence, including its X profile and YouTube account, and shut down its Telegram channel; police indicated some attempted attacks against government websites were successful but did not publicly name the affected institutions.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
Following the investigation and arrests, a court ordered the seizure of the group's X and YouTube accounts, and authorities shut down its Telegram channel. The action disrupted the group's public communications and recruitment infrastructure.
Spanish authorities later arrested two more alleged Anonymous Fénix members described as the most active participants, in Ibiza and Móstoles. Reporting indicates these detentions occurred earlier in February 2026.
In May 2025, Spain's Guardia Civil arrested two suspected key members of Anonymous Fénix in Alcalá de Henares and Oviedo. Authorities identified them as the group's alleged administrator and moderator, or leaders.
After the late-October 2024 DANA storm and flash floods in Valencia, Anonymous Fénix allegedly escalated attacks on public administration websites, blaming authorities for the tragedy. Some government website attacks were reported to have succeeded.
Authorities said the group's attacks against Spanish ministries, political parties, public institutions, and some South American targets intensified from September 2024. The campaign involved DDoS attacks alongside online propaganda and recruitment.
Spanish authorities said the hacktivist group Anonymous Fénix began operating in April 2023. The group used X and Telegram to spread anti-institution messaging, repost news, and recruit participants for hacktivist activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
sentinelone.com
Open sourcescworld.com
Open sourcego.theregister.com
Open sourcehelpnetsecurity.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.