{"id":1216,"date":"2026-08-20T12:26:52","date_gmt":"2026-08-20T06:56:52","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1216"},"modified":"2026-08-20T12:27:36","modified_gmt":"2026-08-20T06:57:36","slug":"spain-government-employee-doxing-identity-risk","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/spain-government-employee-doxing-identity-risk\/","title":{"rendered":"Spain&#8217;s Doxing Arrest Highlights Identity Risk From Aggregated Government Employee Data"},"content":{"rendered":"<p>The recent doxing arrest in Spain has drawn attention to the growing security risks associated with employee data exposure. Spanish authorities have arrested a suspected doxer accused of leaking sensitive data linked to employees at several critical state institutions. The affected organizations include the National Cybersecurity Institute (INCIBE), law enforcement agencies, and national security bodies.<\/p>\n<p>Investigators have not reported a direct compromise of the organizations&#8217; systems. However, the case highlights how threat actors can create serious security risks by collecting and exposing employee information from multiple sources.<\/p>\n<p>For public-sector organizations and enterprises, the incident is an important reminder. Cyber risk extends beyond network intrusions and malware infections. Detailed employee information can also be valuable to attackers.<\/p>\n<p>Data such as contact details, job roles, and other identifiers can help threat actors build detailed profiles of potential targets. They can then use this information to launch targeted phishing attacks, impersonation attempts, and account-compromise campaigns against high-value personnel.<\/p>\n<h2>Understanding the Attack<\/h2>\n<p>Based on information released by Spanish authorities and INCIBE, the incident appears to be a case of data aggregation and correlation rather than a confirmed breach of the affected organizations&#8217; internal systems. This distinction is important because it reflects a growing threat model in which attackers create valuable intelligence assets without needing to compromise a target&#8217;s infrastructure directly.<\/p>\n<p>Threat actors increasingly assemble datasets from multiple sources, including:<\/p>\n<ul>\n<li>Historical breach databases and previously leaked credentials.<\/li>\n<li>Credential dumps circulating on underground forums and data-sharing communities.<\/li>\n<li>Open-source intelligence (OSINT) gathered from public websites, government records, and online directories.<\/li>\n<li>Social media platforms that reveal employment history, organizational relationships, and personal details.<\/li>\n<li>Dark web and cybercriminal marketplaces where fragmented data can be purchased, exchanged, or enriched.<\/li>\n<\/ul>\n<p>When combined and correlated, these sources can produce comprehensive identity profiles that expose:<\/p>\n<ul>\n<li>Personal identifiers and contact information.<\/li>\n<li>Professional email addresses.<\/li>\n<li>Job titles and organizational roles.<\/li>\n<li>Institutional affiliations and reporting structures.<\/li>\n<li>Historical credential exposure and account associations.<\/li>\n<\/ul>\n<p>The operational value of these profiles extends beyond data exposure itself. By understanding an individual&#8217;s role, responsibilities, and professional relationships, attackers can craft highly convincing social-engineering campaigns with significantly greater success rates than generic phishing attempts.<\/p>\n<p>For example, an adversary equipped with curated employee data may impersonate:<\/p>\n<ul>\n<li>Internal IT administrators requesting credential verification.<\/li>\n<li>Government agencies or law enforcement contacts.<\/li>\n<li>Trusted vendors and contractors.<\/li>\n<li>Senior executives or department leaders.<\/li>\n<li>Security teams conducting incident-response activities.<\/li>\n<\/ul>\n<p>Because attackers use accurate organizational context and personal information in these communications, they can more easily overcome user suspicion and evade traditional awareness training. The result is a lower-cost attack path that enables credential theft, account compromise, and unauthorized access without requiring an initial technical exploit against the target organization.<br \/>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/The-Ultimate-Guide-to-XDR-Extended-Detection-and-Response-2.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>The Ultimate Guide to XDR<\/h4><p>Learn how XDR unifies endpoint, network, cloud, and identity security to detect and stop sophisticated threats faster.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/xdr-extended-detection-and-response\/\" aria-label=\"The Ultimate Guide to XDR\"><\/a><\/div><\/div><\/div><\/p>\n<h2>The Hexnode Solution<\/h2>\n<p>Incidents like this demonstrate that security risks often emerge long after data is exposed. Once employee information becomes available through breach datasets, OSINT sources, or public records, organizations must assume that threat actors may attempt to weaponize that intelligence through phishing, impersonation, and account-compromise campaigns.<\/p>\n<p>A strong defense therefore requires more than preventing data exposure. Organizations need controls that can validate user trust, device trust, and account behavior before access is granted to sensitive resources.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/\" rel=\"noopener\">Hexnode UEM<\/a> helps organizations enforce a compliant device posture by ensuring that only authorized, managed, and policy-compliant endpoints can access corporate applications and data. This reduces the likelihood that compromised credentials alone can be used to gain access from unmanaged or untrusted devices.<\/p>\n<p>To further strengthen identity-centric security, organizations can implement controls such as:<\/p>\n<ul>\n<li><strong>Device compliance enforcement<\/strong> before application access is granted.<\/li>\n<li><strong>Conditional access policies<\/strong> based on device trust and risk signals.<\/li>\n<li><strong>Privileged access restrictions<\/strong> for high-risk accounts and sensitive resources.<\/li>\n<li><strong>Continuous monitoring<\/strong> of endpoint security posture across managed devices.<\/li>\n<\/ul>\n<p>In scenarios where attackers leverage exposed employee information for targeted social-engineering campaigns, <a href=\"https:\/\/www.hexnode.com\/xdr\/\" rel=\"noopener\">Hexnode XDR<\/a> can provide additional visibility by correlating signals across multiple security layers. This includes:<\/p>\n<ul>\n<li>Suspicious authentication activity.<\/li>\n<li>Phishing detections and user-reported phishing events.<\/li>\n<li>Browser-based threat indicators.<\/li>\n<li>Endpoint telemetry and security events.<\/li>\n<li>Credential-access attempts.<\/li>\n<li>Anomalous account behavior that may indicate account takeover or impersonation activity.<\/li>\n<\/ul>\n<p>By combining device trust, identity-aware access controls, and cross-domain threat detection, organizations can significantly strengthen their security posture. Additionally, these measures can reduce the downstream impact of employee data exposure. Therefore, organizations can more effectively identify and contain attacks before they result in unauthorized access. Ultimately, this layered approach helps improve resilience against increasingly targeted cyber threats.<\/p>\n<h2>Conclusion<\/h2>\n<p>The Spanish doxing case illustrates an increasingly common challenge for security teams: attackers do not always need to breach systems to create meaningful risk. By aggregating data from previous breaches, public sources, and OSINT channels, threat actors can build detailed employee profiles that enable highly targeted social-engineering and account-compromise campaigns.<\/p>\n<p>For organizations, the lesson extends beyond preventing unauthorized access to networks and applications. Employee identity data has become part of the attack surface, and exposures can create long-term security implications even when no new breach has occurred.<\/p>\n<p>To reduce risk, security leaders should prioritize:<\/p>\n<ul>\n<li><strong>Identity protection<\/strong> for employees, particularly those in sensitive or privileged roles.<\/li>\n<li><strong>Stronger account recovery and verification processes<\/strong> that are resistant to social-engineering attempts.<\/li>\n<li><strong>Phishing-resistant authentication controls<\/strong> and conditional access policies.<\/li>\n<li><strong>Continuous monitoring for suspicious account activity<\/strong> following known data exposures.<\/li>\n<li><strong>Security awareness programs<\/strong> focused on targeted impersonation and spear-phishing threats.<\/li>\n<\/ul>\n<p>As attackers increasingly rely on data aggregation and identity-based targeting, organizations can limit the impact of employee data exposure and prevent follow-on attacks by strengthening identity controls, enforcing device trust, and proactively detecting threats.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/What-makes-Hexnode-the-go-to-UEM-vendor-in-the-market_Thumbnails-for-white-papers-1.webp?format=webp\" class=\"resource-box__image\" alt=\"What-makes-Hexnode-the-go-to-UEM-vendor-in-the-market_Thumbnails-for-white-papers\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/What-makes-Hexnode-the-go-to-UEM-vendor-in-the-market_Thumbnails-for-white-papers-1.webp?format=webp 960w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/What-makes-Hexnode-the-go-to-UEM-vendor-in-the-market_Thumbnails-for-white-papers-1-300x225.webp?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/What-makes-Hexnode-the-go-to-UEM-vendor-in-the-market_Thumbnails-for-white-papers-1-768x576.webp?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/What-makes-Hexnode-the-go-to-UEM-vendor-in-the-market_Thumbnails-for-white-papers-1-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"What-makes-Hexnode-the-go-to-UEM-vendor-in-the-market_Thumbnails-for-white-papers\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured Resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            What makes Hexnode the go-to UEM vendor?\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Download the white paper to learn why you should choose Hexnode, while other vendors in the market claim to be better than Hexnode.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/white-papers\/what-makes-hexnode-the-go-to-uem-vendor-in-the-market\/'>\n                            Get the Whitepaper\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Can attackers create a security risk without breaching an organization&#8217;s systems?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Yes. Attackers can collect and correlate information from previous data breaches, public records, social media, and other sources to build detailed employee profiles. These profiles can then be used to support phishing, impersonation, and account takeover attempts.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Why is employee data valuable to cybercriminals?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Employee information provides context that makes social-engineering attacks more convincing. Details such as job titles, email addresses, reporting structures, and organizational affiliations can help attackers impersonate trusted contacts or tailor phishing messages to specific individuals.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">How is data aggregation different from a traditional data breach?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>A traditional breach typically involves unauthorized access to an organization&#8217;s systems. Data aggregation, on the other hand, involves collecting information from multiple existing sources and combining it into a more valuable dataset, often without directly compromising the target organization.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What types of attacks can result from employee data exposure?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Exposed employee information can enable spear-phishing, impersonation scams, credential theft attempts, account takeover campaigns, and other forms of targeted social engineering. The more context attackers have, the more credible their communications can appear.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What should organizations do after employee information is exposed?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Organizations should strengthen identity protection measures, review account recovery procedures, enforce phishing-resistant authentication where possible, and monitor for suspicious account activity. Security teams should also be alert to impersonation attempts targeting employees and executives.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Why are privileged and high-profile employees often targeted first?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>These individuals typically have access to sensitive systems, data, or business processes. Attackers may focus on them because a successful compromise can provide broader access or create opportunities for further attacks within the organization.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>The recent doxing arrest in Spain has drawn attention to the growing security risks associated&#8230;<\/p>\n","protected":false},"author":8,"featured_media":1217,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[10,13],"class_list":["post-1216","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-phishing","category-identity-abuse","product_category-identity-provider","tab_group-identity-and-phishing"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Spain&#039;s Doxing Arrest Highlights Identity Risk From Aggregated Government Employee Data<\/title>\n<meta name=\"description\" content=\"Doxing arrest in Spain highlights how employee data exposure can enable phishing, impersonation, and account attacks\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/spain-government-employee-doxing-identity-risk\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Spain&#039;s Doxing Arrest Highlights Identity Risk From Aggregated Government Employee Data\" \/>\n<meta property=\"og:description\" content=\"Doxing arrest in Spain highlights how employee data exposure can enable phishing, impersonation, and account attacks\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/spain-government-employee-doxing-identity-risk\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-20T06:56:52+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-20T06:57:36+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Doxing-arrest-in-Spain.webp?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"535\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Alanna River\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Alanna River\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/spain-government-employee-doxing-identity-risk\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/spain-government-employee-doxing-identity-risk\\\/\"},\"author\":{\"name\":\"Alanna River\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\"},\"headline\":\"Spain&#8217;s Doxing Arrest Highlights Identity Risk From Aggregated Government Employee Data\",\"datePublished\":\"2026-08-20T06:56:52+00:00\",\"dateModified\":\"2026-08-20T06:57:36+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/spain-government-employee-doxing-identity-risk\\\/\"},\"wordCount\":1265,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/spain-government-employee-doxing-identity-risk\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Doxing-arrest-in-Spain.webp?format=webp\",\"articleSection\":[\"Phishing\",\"Identity Abuse\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/spain-government-employee-doxing-identity-risk\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/spain-government-employee-doxing-identity-risk\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/spain-government-employee-doxing-identity-risk\\\/\",\"name\":\"Spain's Doxing Arrest Highlights Identity Risk From Aggregated Government Employee Data\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/spain-government-employee-doxing-identity-risk\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/spain-government-employee-doxing-identity-risk\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Doxing-arrest-in-Spain.webp?format=webp\",\"datePublished\":\"2026-08-20T06:56:52+00:00\",\"dateModified\":\"2026-08-20T06:57:36+00:00\",\"description\":\"Doxing arrest in Spain highlights how employee data exposure can enable phishing, impersonation, and account attacks\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/spain-government-employee-doxing-identity-risk\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/spain-government-employee-doxing-identity-risk\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/spain-government-employee-doxing-identity-risk\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Doxing-arrest-in-Spain.webp?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Doxing-arrest-in-Spain.webp?format=webp\",\"width\":1024,\"height\":535,\"caption\":\"Doxing-arrest-in-Spain\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/spain-government-employee-doxing-identity-risk\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Spain&#8217;s Doxing Arrest Highlights Identity Risk From Aggregated Government Employee Data\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\",\"name\":\"Alanna River\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"caption\":\"Alanna River\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/alanna-river\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Spain's Doxing Arrest Highlights Identity Risk From Aggregated Government Employee Data","description":"Doxing arrest in Spain highlights how employee data exposure can enable phishing, impersonation, and account attacks","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/spain-government-employee-doxing-identity-risk\/","og_locale":"en_US","og_type":"article","og_title":"Spain's Doxing Arrest Highlights Identity Risk From Aggregated Government Employee Data","og_description":"Doxing arrest in Spain highlights how employee data exposure can enable phishing, impersonation, and account attacks","og_url":"https:\/\/www.hexnode.com\/threat-watch\/spain-government-employee-doxing-identity-risk\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-08-20T06:56:52+00:00","article_modified_time":"2026-08-20T06:57:36+00:00","og_image":[{"width":1024,"height":535,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Doxing-arrest-in-Spain.webp?format=webp","type":"image\/webp"}],"author":"Alanna River","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Alanna River","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/spain-government-employee-doxing-identity-risk\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/spain-government-employee-doxing-identity-risk\/"},"author":{"name":"Alanna River","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64"},"headline":"Spain&#8217;s Doxing Arrest Highlights Identity Risk From Aggregated Government Employee Data","datePublished":"2026-08-20T06:56:52+00:00","dateModified":"2026-08-20T06:57:36+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/spain-government-employee-doxing-identity-risk\/"},"wordCount":1265,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/spain-government-employee-doxing-identity-risk\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Doxing-arrest-in-Spain.webp?format=webp","articleSection":["Phishing","Identity Abuse"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/spain-government-employee-doxing-identity-risk\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/spain-government-employee-doxing-identity-risk\/","url":"https:\/\/www.hexnode.com\/threat-watch\/spain-government-employee-doxing-identity-risk\/","name":"Spain's Doxing Arrest Highlights Identity Risk From Aggregated Government Employee Data","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/spain-government-employee-doxing-identity-risk\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/spain-government-employee-doxing-identity-risk\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Doxing-arrest-in-Spain.webp?format=webp","datePublished":"2026-08-20T06:56:52+00:00","dateModified":"2026-08-20T06:57:36+00:00","description":"Doxing arrest in Spain highlights how employee data exposure can enable phishing, impersonation, and account attacks","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/spain-government-employee-doxing-identity-risk\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/spain-government-employee-doxing-identity-risk\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/spain-government-employee-doxing-identity-risk\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Doxing-arrest-in-Spain.webp?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Doxing-arrest-in-Spain.webp?format=webp","width":1024,"height":535,"caption":"Doxing-arrest-in-Spain"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/spain-government-employee-doxing-identity-risk\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Spain&#8217;s Doxing Arrest Highlights Identity Risk From Aggregated Government Employee Data"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64","name":"Alanna River","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","caption":"Alanna River"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/alanna-river\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1216","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1216"}],"version-history":[{"count":2,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1216\/revisions"}],"predecessor-version":[{"id":1220,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1216\/revisions\/1220"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1217"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1216"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1216"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}