Back to Exposure Report
Defense / GovernmentJuly 2026Spain

Indra Sistemas

TheGentlemen threat group claims Spain's largest defense and IT services contractor. Systems supporting NATO and the Spanish military potentially affected.

Defense systems dataCorporate informationUnder investigation
1

What happened?

TheGentlemen threat group claimed a breach at Indra Sistemas, Spain's largest defense and IT services contractor. Indra operates air traffic control systems, defense electronics, simulation platforms, transportation systems, and critical infrastructure technology.

The targeting of a defense contractor represents escalation beyond typical commercial ransomware. National security implications emerge when contractors supporting military operations are compromised.

2

What data was actually inside?

Defense contractors hold classified information, weapons systems specifications, military personnel data, and infrastructure details. Even unclassified business data can reveal procurement schedules, technology capabilities, and strategic priorities.

Spain is a NATO member. Indra systems support alliance operations. A breach potentially affects military capabilities beyond Spanish borders.

3

Who gets hurt and how?

Spanish military operations. NATO alliance activities that depend on Indra systems. Government agencies using Indra-built infrastructure. Air traffic control systems that keep aircraft safe. The scope spans critical national infrastructure.

Defense contractor breaches create both immediate and long-term harm. Immediate: operational security compromise. Long-term: intelligence value to adversaries who may use the data for years.

4

What did they think they were doing right?

Defense contractors operate under strict security requirements. Government contracts mandate specific cybersecurity standards. Spain's National Security Council oversees critical infrastructure protection. Compliance frameworks exist at multiple levels.

But compliance doesn't equal security against sophisticated threats. TheGentlemen demonstrated capability against a well-resourced target. The targeting itself signals threat actor ambitions.

5

What did they not know about their own data?

Defense contractors accumulate data across years of government contracts. Classified and unclassified projects. Completed and ongoing programs. Historical documentation that may no longer be operationally relevant but retains intelligence value.

Understanding what sensitive data exists—and ensuring appropriate segmentation between classified and unclassified systems—requires comprehensive data visibility.

If your business runs on databases, you probably have similar records—customer data, credentials, financial information. Do you know what's actually in yours?

6

What does attribution look like the morning after?

Spanish intelligence and defense authorities investigate. NATO involvement if alliance systems or data were affected. Investigation scope extends beyond commercial breach response to national security assessment.

The line between cybercrime and cyber espionage blurs when ransomware groups target defense contractors. The data value extends beyond extortion potential to intelligence gathering.

7

What would have changed the outcome?

Comprehensive classification and segmentation of defense-related data—ensuring sensitive national security information isn't accessible through compromised commercial systems.

Defense contractors operate at the intersection of commercial and classified environments. The security of one affects the other. Organizations that maintain strict segmentation, comprehensive data classification, and visibility into what exists where are better positioned to limit the scope when breaches occur.

Indra Sistemas found out the hard way.

Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.