Spanish police arrest suspected helper of pro-Russian hacking crews

The man in Palencia allegedly helped a Ukrainian hacker flee toward Russia and supported groups linked to attacks on U.S. water and energy sites.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: A dim control room at a water treatment facility at night
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Spain's National Police arrested a man in Palencia in March 2026 on suspicion of aiding pro-Russian hacking groups, acting on a tip from the FBI.
  • The suspect is accused of helping a Ukrainian hacker working for the CyberArmy of Russia Reborn (CARR) escape toward Russia via Poland and Belarus.
  • Investigators seized computers and cryptocurrency storage devices, and froze wallets said to hold money from sales of stolen data.
  • CARR has been tied to cyberattacks on water and food plants in the United States, and loosely linked to the Russian military hacking unit known as Sandworm.
  • Prosecutors are considering charges including membership in a terrorist organisation, glorification of terrorism, and computer damage.

Spanish police have arrested a man they say worked as a fixer for pro-Russian hacking groups, including one crew accused of meddling with American water and energy systems.

The man lived in Palencia, a quiet city in northern Spain. Officers raided his home in March 2026 and seized laptops along with cryptocurrency storage hardware. They also froze digital wallets that, investigators say, held proceeds from selling stolen data.

BleepingComputer first reported the arrest.

Who are these hacking groups?

The suspect is accused of supporting CARR and a related crew called Z-Pentest. Both call themselves hacktivists, meaning hackers who claim to act for a political cause rather than for money. The gap between that label and their actual behaviour is the whole story here.

A U.S. Indictment of another alleged CARR member, Victoria Eduardovna Dubranova, said the group attacked water utilities and food-processing plants inside the United States. That's the kind of intrusion that risks tap water and food safety, not just a defaced webpage. We looked at the broader pattern of state-linked groups probing water infrastructure in our report from 3 July 2026, which found the tools being used were embarrassingly basic.

The U.S. Government has previously sanctioned two other suspected CARR members: Yuliya Vladimirovna Pankratova and Denis Olegovich Degtyarenko. They were linked to attacks on SCADA systems at an American energy firm. SCADA are the computers that control physical processes: valves, pumps, circuit breakers.

Researchers have also loosely tied CARR to APT44, better known as Sandworm, a unit inside Russian military intelligence with a long record of destructive attacks. Sandworm has a habit of operating through hacktivist fronts, which makes the CARR connection notable rather than surprising.

What did the arrested man actually do?

The Spanish police say he gave logistical and operational support to a Ukrainian hacker working for CARR and tried to arrange that hacker's escape through Poland and Belarus toward Russia.

He used encrypted messaging apps to coordinate with other members, police say. Investigators also say he took part in operations attributed to NoName057(16), a pro-Russian group best known for knocking European government websites offline with floods of junk traffic. Those operations were later promoted on pro-Russian websites to push anti-Western narratives, according to the police statement.

Should ordinary people be worried?

Not directly, but the case is a reminder that "hacktivism" isn't always harmless graffiti. When a group is poking at software that runs a water plant, the risk is physical.

The FBI passed information to Spanish authorities in August 2025. The investigation ran roughly seven months before the March 2026 raid. No formal charges have been filed yet; prosecutors are still weighing the counts under Spanish law.

The suspect remains under investigation while officers work through his seized devices. Groups like CARR don't run on one person, and arrests of the support layer tend to shake loose the operators above them. Watch for more names.

© 2026 Threat Vectr