Ransomware victim disclosure
← All victimsAgencia Estatal de Meteorología
Claimed by Panzer · listed 2 days ago
Status timeline
- ListedSep 11, 2026
- Data leakeddate unknown
At a glance
- Group
- Panzer
- Status
- Data leaked
- Country
- Spain
- Sector
- Government & Defense
- Listed on leak site
- Sep 11, 2026
About the victim
AI dossier — public-source company profileAEMET is Spain's state meteorological agency responsible for weather observation, forecasting, and climate analytics. It provides services to agriculture, aviation, maritime, and emergency response sectors, and conducts research in meteorological science.
- Industry
- Government & Defense - Meteorological Services
Attack summary
Severity: medium — Critical infrastructure (national meteorological service) claimed compromised by ransomware operator, but no proof files, data inventory, or confirmation of exfiltration vs. encryption-only disclosed. Government/defense sector classification elevates from low, but lack of evidence prevents high/critical rating.The Panzer group claims to have compromised AEMET. No specific details about exfiltrated data types, encryption status, or operational impact are provided in the leak post.
What the group claims
Agencia Estatal de Meteorología - AEMET is a governmental agency of Spain that provides comprehensive meteorological services, including weather observation, predictions, and climate analytics. It serves various sectors such as agriculture, aviation, maritime activities, and emergency services. AEMET aims to support public safety and management through accurate weather forecasts, climate data, and educational resources. The agency also engages in research and international collaboration to enhance meteorological science and technology.
Sources
Source
Indexed 2 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

