@FkPoliceAnonOps
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known by the Twitter handle @FkPoliceAnonOps and also referred to as Anonymous Police operates as a hacktivist collective linked to the broader Anonymous movement. Publicly available reporting indicates that the group is based in Spain, which aligns with the geographic focus of its activities. The actor’s primary aliases reflect its antagonistic stance toward law‑enforcement institutions, particularly police organizations in the country. No public sources attribute the group to a state sponsor or a criminal consortium; instead, it is described as part of the decentralized Anonymous network that conducts operations driven by ideological motives. The actor’s identity is therefore framed as a politically motivated hacktivist rather than a financially oriented cybercriminal group.
The actor’s demonstrated targeting centers on Spanish law‑enforcement entities, specifically the police sector, as evidenced by the breach of the Sindicat De Mossos d’Esquadra servers and the subsequent leak of personal data from the mupol.es mutual fund for Spanish policemen. The stated strategic objective of the operation was to protest the Spanish gag law, with the group seeking to expose what it described as the thin veil behind which police hide their actions. Technical details provided in the source material note that the attackers gained access to the telecom unit responsible for investigative crimes within the police department, allowing them to extract names, surnames, personal emails, national identification numbers, and MD5 password hashes before publishing the data online. No specific malware families, exploit kits, or custom tooling are mentioned in the reporting, so the actor’s TTPs are limited to the described initial access via the telecom unit and the subsequent data dump. The most notable publicly reported campaign is the 2016 data leak involving approximately 5,400 police members, which was carried out as a direct response to the gag law and resulted in the widespread dissemination of the compromised information across the internet. This operation remains the primary example of the actor’s activity in open‑source sources.
Incidents
Attributed incidents are available to members.
0 incidents