Confederación Sindical de Comisiones Obreras
Incident posture
Linked entities
- Victim
- Confederación Sindical de Comisiones Obreras
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
A major Spanish trade union suffered a significant cyberattack in which approximately 570 GB of sensitive data was compromised, exposing around 690,000 files across more than a dozen departments including human resources, finance, legal affairs, collective bargaining, and international relations. The intrusion, attributed to the Hunters International threat group believed to be based in Nigeria, involved data exfiltration prior to encryption, a tactic that enables extortion even when victims maintain backups. Initial access was reportedly achieved through targeted phishing emails that tricked employees into executing malware. The breach potentially affects nearly 700 internal employees as well as the union's broader membership of affiliated workers. The organization activated its incident response teams, applied security measures to clean its systems, notified competent authorities, and stated that no critical systems were impacted, with normal operations largely maintained.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
The Confederación Sindical de Comisiones Obreras (CC.OO) suffered a major cyberattack that resulted in the compromise of approximately 570 gigabytes of sensitive organizational data, affecting more than a dozen internal departments. According to sources familiar with the incident, the intrusion into the union's servers exposed around 690,000 files spanning areas including human resources, finance, the legal department, collective bargaining, industrial policy and strategy, international affairs, equality and organization, data protection, and the agri-food division, among other areas of the union's operations. The scale of the breach extended beyond the union's own infrastructure, with potential implications for its roughly 700 employees and the broader population of unionized workers whose information was held within the compromised systems.
The attack has been attributed to the threat group known as Hunters International, an organization reportedly based in Nigeria that specializes in ransomware operations. The group allegedly signaled its intentions to target the union approximately one week before deploying the offensive, giving some prior indication of the impending assault. Hunters International is characterized by the use of advanced encryption systems employing multiple types of algorithms, with data recovery only possible through a decryption key provided by the attackers following payment of the demanded ransom. The Basque cybersecurity agency Cyber Zaintza documented in one of its sectoral reports that the group's most concerning tactic is its focus on data exfiltration prior to encryption, meaning that even victims with functioning backups who decline to pay the ransom still face extortion through the threat of publication or sale of stolen data on dark web marketplaces. The same agency noted that the group's operations typically begin with targeted phishing campaigns using malicious emails designed to trick employees into executing malware, and that Hunters International has rapidly expanded its global presence by attacking organizations across healthcare, education, logistics, and other critical sectors.
This was not the first cybersecurity incident to affect CC.OO. In November 2023, the union experienced a prior cyberattack that disabled its website for several hours. The most recent breach was officially disclosed by the union on February 26, when CC.OO informed the public of a cyberattack against its information systems. In its public statement, the union indicated that its cyber incident response teams had been working from the initial detection to contain and reduce the impact of the incident on the rights and freedoms of affected individuals. The union stated that it had applied the necessary security measures to clean its systems and was conducting an investigation to clarify what had occurred and determine the full scope of the incident. According to the union's official communication, none of its critical systems had been affected in principle, and the overall functioning of its information systems had been normalized. As a precautionary measure, the union notified the relevant authorities of the breach and indicated that it would expand public information in the following days as its investigation progressed.
Sources
Sources available to members: 1 source.