Skip to content
RansomwareContained

Indra Group subsidiary ransomware attack (The Gentlemen)

Spanish defense and technology group Indra confirmed a ransomware attack on one of its subsidiaries after The Gentlemen ransomware gang listed the company on its leak site, saying the impact was minimal and limited to a non-critical environment.

Victim
Indra Group

On 1 July 2026, Indra Group, the Spanish defense, air traffic and information technology company, confirmed that one of its subsidiaries had been hit by a ransomware attack. The confirmation came a day after threat intelligence firm Hackmanac reported that the ransomware gang The Gentlemen had added Indra Group to its data-leak site, starting a countdown of roughly 236 hours (just under ten days) before it would publish or sell the data it claimed to have stolen.

Indra said its security systems detected the attack and that its incident response team (CSIRT) activated containment and analysis protocols immediately. According to the company, the incident had a minimal impact, was confined to a non-critical environment, did not spread to other companies in the group and did not affect operations, with services continuing normally. Indra did not name the affected subsidiary and opened an investigation into the origin of the attack.

What is known about the data

The Gentlemen did not disclose the volume or nature of the data it claimed to hold, and no samples had been published at the time of the company's statement. Indra has not confirmed that any data was taken.

Why it matters

Indra is one of Europe's main defense contractors and a supplier to NATO and Spanish government programs, which makes any intrusion into its corporate perimeter sensitive even when the affected environment is described as non-critical. The Gentlemen, a ransomware operation that emerged in 2025, has been among the most active leak-site operators of 2026, and the case shows that large defense groups remain exposed through subsidiaries with separate IT environments.

Timeline

  1. Threat intelligence firm Hackmanac reports that The Gentlemen ransomware gang has listed Indra Group on its leak site with a countdown of about 236 hours.

  2. Indra confirms a ransomware incident at one of its subsidiaries, contained by its CSIRT, with minimal impact and no effect on group operations.

Sources

  1. escudodigital.comhttps://www.escudodigital.com/ciberseguridad/indra-confirma-haber-sufrido-un-ataque-de-ransomware-aunque-con-un-impacto-minimo.html
  2. eleconomista.eshttps://www.eleconomista.es/industria/noticias/13994155/07/26/indra-investiga-un-ciberataque-de-un-grupo-de-hackers-conocido-como-the-gentlemen.html
  3. incibe.eshttps://www.incibe.es/index.php/incibe-cert/publicaciones/bitacora-de-seguridad/incidente-de-ciberseguridad-en-una-filial-de-indra
  4. cybernews.comhttps://cybernews.com/security/indra-group-ransomware-attack-data-leak/

Related incidents