Quick Summary
AllegedExecutive Summary
Panzer listed Castilla La Mancha on August 17, 2026, identified through SOCRadar’s Dark Web Monitoring service. The target is Spain’s autonomous community government for the central region, administering public services that include education, healthcare, public employment, and regional cloud infrastructure. A regional government of this scale is relatively uncommon in Panzer’s recent portfolio — consistent with the group’s expanding public-sector targeting over the past two months. Panzer recorded 11 other victims in the 60 days preceding this listing. Sectors targeted: Manufacturing, Technology, and Government & Defense. Geographic concentration: Thailand, Spain, and South Korea. Other Spanish or government-sector Panzer listings include DL E&C, Doimo Cucine, Infosat, and SAGASTA sro.
Technical Analysis
SOCRadar’s stealer-log query against castillalamancha[.]es returned 25 records; 24 target castillalamancha[.]es subdomains spanning education portals (educamosclm.castillalamancha[.]es), cloud infrastructure (nube.castillalamancha[.]es), HR and payroll systems (firer.castillalamancha[.]es, oeps-sescam.castillalamancha[.]es), public employment alerts (alertassiaci.castillalamancha[.]es), and an HR pre-production environment. Eighteen records classified as external users accessing organization-owned systems; six indeterminate due to username masking. Log dates cluster August 14-17, 2026 — directly preceding the leak-site publication. No definitive employee-domain credentials appeared in this slice. Username masking and paginated dataset coverage are standard limitations; adjacent slices may hold additional records. The credential pattern is more than background noise. Multiple internal subsystems exposed within days of the public listing is consistent with a post-compromise credential-staging phase. The concentration across HR, payroll, cloud infrastructure, and education portals points to systematic harvesting from live victim infrastructure — not a sweep of stale credentials. This fits Panzer’s documented kill chain. Castilla La Mancha’s broad citizen data exposure across these subsystems elevates the public impact well beyond a typical enterprise ransomware incident.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.