Security1 distinct publisher3 min readPublished
The Spanish police and military profiles carry photographs, phones and address-book contacts. Sources cited by Estrella Digital put a former GRU structure behind the group.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The spine of this file is a Telegram handle. That matters more than the page count: 1,014 identifier appearances reduce to 994 unique ones [3], a repetition rate of about two percent [4]. Raw exports out of a breached personnel system do not usually arrive that clean. And 994 profiles spread over 499 pages works out at roughly two per page [5], which is the footprint of a per-person template with room for a photograph and a contact block, not a spreadsheet dump with a thousand rows on twenty sheets.
The depth varies from one person to the next [16], but the format holds, and in many entries it extends past the named individual into several additional numbers listed under the heading "contacts in his address book" [10]. That is the part with the longest tail. A phone number harvested from someone else's phone stays valid whether or not its owner ever hears about this document.
What the file does not establish is who is in it. The collective titled it a listing of the Spanish security forces [6], yet some profiles state no profession or corps at all [6], and Estrella Digital is explicit that 994 counts individualised profiles rather than personnel whose membership can be verified from the contents [8]. Others in the file are labelled from the first page as members of the Spanish army, the Guardia Civil or the Cuerpo Nacional de Policia, with photograph, telephone, email, identifier and address-book contacts attached [7]. So the count officials will end up quoting is a count the publisher supplied about its own work product. The checking is being done downstream, by police unions and Guardia Civil associations who have identified some of the profiles and taken the matter to Interior [9].
On the sponsorship question, the sourcing is thinner than the file. Sources accessed by Estrella Digital say the collective inherits part of a hacker structure that previously operated linked to the GRU, Russian military intelligence, and later ran under a formally civilian arrangement [14]; sector sources cited by the same outlet place the GRU behind the group [15]. Both are unnamed and single-outlet, and nothing in a 499-page dossier set corroborates a chain of command. The on-record material is narrower and still useful: the group surfaced publicly in March 2022, weeks into the invasion of Ukraine [11], the CCN, which sits inside the CNI, has carried it in annual national-security cyberthreat reporting almost from the start of its activity [12], and the Ertzaintza's cybersecurity agency has placed it among the actors with the most attacks against Spain and other backers of Kyiv [13].
Those listings were earned by attack volume. A curated set of individual dossiers on serving personnel is a different output with a different consumer, and it does not decay the way a disruption campaign does: the traffic stops, the phone numbers do not. Estrella Digital says it also obtained a roster of people who form or have formed part of NoName057(16) [2], which is the one thread in this story that could turn attribution from sourcing into names.
Ranked by verification strength, evidence, and original report placement.
A 499-page document attributed to NoName057(16) contains photographs, telephone numbers, emails, Telegram accounts and other data corresponding to 994 different profiles that the collective links to members of the Spanish Armed Forces and the State Security Forces and Corps.
Estrella Digital says it analysed the complete file and also obtained a list of hackers who form or have formed part of NoName057(16).
The 499 pages contain 1,014 appearances of Telegram identifiers; after discarding repetitions there are 994 unique identifiers.
The hackers titled the document a listing of the Spanish security forces, but in some of the profiles the profession or the corps the person belongs to is not expressly stated.
From the first page, people identified as members of the Spanish army, the Guardia Civil or the Cuerpo Nacional de Policia appear alongside a photograph, telephone number, email, identifier and contacts from their address book.
It is not possible to assure that all 994 are police officers, Guardia Civil or military personnel; 994 is the number of individualised profiles the file contains, not the number of officers and soldiers whose membership can be verified from its contents alone.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Document-level counting is checkable; attribution and provenance are not
The strongest evidence is internal and arithmetic: the outlet reports counting 1,014 Telegram identifier appearances resolving to 994 unique across 499 pages, and describes concrete per-profile fields. That is verifiable in principle and internally consistent, and the article volunteers its own limit — 994 profiles is not a verified count of serving officers. Against that, everything rests on one publisher's private access to the file and to an alleged member list, the GRU lineage comes from unnamed sources with no official attribution of this group, and no state body or affected corps is quoted confirming the file. Partial confirmation by police unions and Guardia Civil associations is the only external check reported.
Real-world footprint confirmed only partially, by affected staff bodies
Read as real-world consequence rather than product uptake, the story has a measurable but shallow footprint: the file is in public circulation, and police unions and Guardia Civil associations have identified some profiles as their members and escalated to the Interior Ministry. Official tracking of NoName057(16) by the Centro Criptológico Nacional and the Ertzaintza establishes the actor as an established threat rather than a novelty. But there is no reported number of confirmed victims, no institutional confirmation of the file, and no disclosed remediation, notification or countermeasure, so consequence remains largely unquantified.
Headline count outruns what is verified, though the article self-limits
The framing leans on the round '994 dossiers on police, military and Guardia Civil' and on a GRU pedigree drawn from unnamed sources, both of which sit above the evidentiary floor: the outlet itself says membership cannot be established from the file alone, and the official GRU material it cites concerns APT28 and Unit 26165 rather than NoName057(16). The overstatement is modest rather than severe because the article publishes its own caveat prominently, discloses the de-duplication step behind the 994 figure, and the underlying exposure pattern — photos, phones and harvested address books — is described in verifiable detail.
Single-outlet exclusive with unnamed sources supplying the headline attribution
The reporting incentive is visible and material: one publisher holds the file and an alleged member list, repeatedly foregrounds that exclusive access, and derives its most striking claim — Russian military intelligence behind the group — from sources it does not name. Anonymous cybersecurity-sector and intelligence-adjacent sources have their own reasons to promote a state-attribution narrative. Counterweights exist: the article states its verification limit, shows its counting method, and cites named official bodies for the group's threat history, so the incentive is scoop-driven rather than commercial or vendor-driven.
Low-moderate: one publisher, checkable counts, uncorroborated attribution
Confidence is held down by structure rather than by contradiction. There is a single source in the cluster, no official confirmation, no second outlet, and no provenance account for the data; the central attribution is anonymous. Confidence is not lower because the document-level facts are specific, self-consistent and accompanied by an explicit statement of their limits, and because the actor's presence in CCN/CNI and Ertzaintza reporting is independently checkable in principle.
build
Europe's arms plants are burning, and the arsonists are being hired locally1 distinct publisher
build
A session that read "finished" and "still executing" was a slow queue, not a dropped handshake1 distinct publisher
build
OpenClaw makes the channel the architecture, and the reasoning loop a lodger1 distinct publisher
security
Aeternum puts botnet C2 on Polygon, and leaves defenders no domain to seize1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 25, 2026