CSIDB logo
Incident

Confederación Sindical de Comisiones Obreras

Incident posture

Attack window
Feb 2025
Location
Spain
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 17:43

Linked entities

Victim
Confederación Sindical de Comisiones Obreras
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Feb 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A major Spanish trade union suffered a significant cyberattack in which approximately 570 GB of sensitive data was compromised, exposing around 690,000 files across more than a dozen departments including human resources, finance, legal affairs, collective bargaining, and international relations. The intrusion, attributed to the Hunters International threat group believed to be based in Nigeria, involved data exfiltration prior to encryption, a tactic that enables extortion even when victims maintain backups. Initial access was reportedly achieved through targeted phishing emails that tricked employees into executing malware. The breach potentially affects nearly 700 internal employees as well as the union's broader membership of affiliated workers. The organization activated its incident response teams, applied security measures to clean its systems, notified competent authorities, and stated that no critical systems were impacted, with normal operations largely maintained.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

The Confederación Sindical de Comisiones Obreras (CC.OO) suffered a major cyberattack that resulted in the compromise of approximately 570 gigabytes of sensitive organizational data, affecting more than a dozen internal departments. According to sources familiar with the incident, the intrusion into the union's servers exposed around 690,000 files spanning areas including human resources, finance, the legal department, collective bargaining, industrial policy and strategy, international affairs, equality and organization, data protection, and the agri-food division, among other areas of the union's operations. The scale of the breach extended beyond the union's own infrastructure, with potential implications for its roughly 700 employees and the broader population of unionized workers whose information was held within the compromised systems.

The attack has been attributed to the threat group known as Hunters International, an organization reportedly based in Nigeria that specializes in ransomware operations. The group allegedly signaled its intentions to target the union approximately one week before deploying the offensive, giving some prior indication of the impending assault. Hunters International is characterized by the use of advanced encryption systems employing multiple types of algorithms, with data recovery only possible through a decryption key provided by the attackers following payment of the demanded ransom. The Basque cybersecurity agency Cyber Zaintza documented in one of its sectoral reports that the group's most concerning tactic is its focus on data exfiltration prior to encryption, meaning that even victims with functioning backups who decline to pay the ransom still face extortion through the threat of publication or sale of stolen data on dark web marketplaces. The same agency noted that the group's operations typically begin with targeted phishing campaigns using malicious emails designed to trick employees into executing malware, and that Hunters International has rapidly expanded its global presence by attacking organizations across healthcare, education, logistics, and other critical sectors.

This was not the first cybersecurity incident to affect CC.OO. In November 2023, the union experienced a prior cyberattack that disabled its website for several hours. The most recent breach was officially disclosed by the union on February 26, when CC.OO informed the public of a cyberattack against its information systems. In its public statement, the union indicated that its cyber incident response teams had been working from the initial detection to contain and reduce the impact of the incident on the rights and freedoms of affected individuals. The union stated that it had applied the necessary security measures to clean its systems and was conducting an investigation to clarify what had occurred and determine the full scope of the incident. According to the union's official communication, none of its critical systems had been affected in principle, and the overall functioning of its information systems had been normalized. As a precautionary measure, the union notified the relevant authorities of the breach and indicated that it would expand public information in the following days as its investigation progressed.

Sources

Sources available to members: 1 source.

CSIDB