Spain Charges Russian Hacktivist as Terrorist
Spain's arrest signals a shift in cybercrime prosecution.
Model Diplomat8 min readEurope

Spain Uses Terror Law on Russian Hacktivist — Attribution Turning Point
Spain's arrest of a Palencia man tied to Cyber Army of Russia Reborn shows Western states now prosecuting Russian hacktivists as terrorism-linked state proxies, not amateurs.
The Spanish National Police disclosed on July 6, 2026 that it had arrested a Palencia resident in March on charges including "collaboration with a terrorist organisation" for logistically supporting Cyber Army of Russia Reborn (CARR), also known as Z-Pentest, and NoName057(16) — the first time a European jurisdiction has applied its anti-terrorism penal code to a pro-Kremlin "hacktivist" facilitator. The move matters because it locks in a prosecutorial doctrine — one Western capital after another now treating nominally independent Russian DDoS crews as proxies of the Russian state, indictable under terrorism, sabotage and destabilisation statutes rather than routine computer-misuse laws. That reframing, and not the arrest itself, is the story: Madrid, Washington and Brussels are building a cross-jurisdictional attribution stack that no longer requires proof of direct GRU tasking to prosecute low-level participants, a shift that will reshape how state-sponsored cyber operations are contested across Global Politics.
What Spain actually did — and why the charge sheet is the story
According to CyberScoop, Spain's Policía Nacional detained the unnamed suspect at his home in Palencia after an August 2025 tip from the FBI's Los Angeles field office. Investigators seized computers, cryptocurrency storage devices and froze a crypto wallet used to receive payments. Officials allege the suspect provided logistical support to a Ukrainian hacker affiliated with Z-Pentest — including helping him exfiltrate through Poland and Belarus into Russia — and participated in DDoS actions later claimed by NoName057(16) on "specialised portals related to geopolitics."
The FBI, in a LinkedIn post from its cyber division, described the arrest as part of Operation Riptide, a global campaign the bureau says targets cybercriminal infrastructure and the financial networks that sustain it. Security Affairs reports that Spanish prosecutors have kept the specific indictment sealed but confirmed the terrorism-collaboration count — the same statute historically used against jihadist facilitators, as evidenced by prior
Moncloa announcements on Daesh-related cells dismantled in Barcelona and Melilla.
That legal choice is not cosmetic: Spain is telling the Audiencia Nacional that a Russian-aligned DDoS network qualifies as a "terrorist organisation" for prosecution purposes, an assertion that raises the ceiling on sentencing and unlocks a broader arsenal of investigative powers under Spanish criminal law. A Spanish parliamentary report submitted to the Cortes Generales in 2025 already warned that "the convergence between organised crime and state action complicates attribution, increases the complexity of the threat environment, and reduces the thresholds of political and legal responsibility" — language that reads, in retrospect, as the doctrinal groundwork for exactly this prosecution.
The attribution ratchet: from "patriotic volunteers" to state proxies
For three years, Western agencies treated CARR and NoName057(16) as messy, semi-autonomous "patriotic" collectives. That posture is collapsing. A 2025 working paper from the German Institute for International and Security Affairs (SWP Berlin) notes that a December 2025 joint cybersecurity advisory — signed by multiple Western agencies — directly linked CARR to Russian military intelligence Unit 26165 and assessed that NoName057(16) was "established by the Kremlin's Center for the Study and Network Monitoring of the Youth Environment (CISM)," with CISM employees directly involved in developing the DDoSia platform, funding infrastructure and selecting targets.
The Council on Foreign Relations' Cyber Operations Tracker formalised this shift in early 2025, adding Cyber Army of Russia Reborn, XakNet and Solntsepek as affiliated personas of GRU Sandworm rather than independent hacktivist brands. Mandiant reaches the same conclusion, assessing GRU coordination with moderate confidence, as summarised by
CSIS. The UK government went further in 2025, publishing a detailed
profile of GRU cyber and hybrid threat operations that designated 14 Unit 26165 officers, exposed six for the first time, and warned NATO partners "to prepare for the potential redirection of GRU cyber and hybrid threats towards European partners."
This matters legally. Under EU sanctions regime Council Implementing Regulation 2026/259, adopted January 29, 2026, the Council needs only to demonstrate that a person is engaged in "actions attributable to the Government of the Russian Federation which undermine or threaten democracy, the rule of law, stability and security" of the Union. That framework, established October 8, 2024, is being aggressively populated:
Council Decision (CFSP) 2026/1351 added ten more individuals on June 15, 2026, following March 16, 2026 conclusions that "strongly condemned and held accountable the Russian Federation and its proxies for their persistent, coordinated and long-standing hybrid campaigns." An earlier July 15, 2025 Council listing of "nine individuals and six entities responsible for destabilising actions in the EU and Ukraine" — announced by the
Consilium — brought total listings under this regime to 47 individuals and 15 entities.
From DDoS nuisance to physical damage — the escalation curve
The prosecutorial hardening tracks a real escalation in what these groups actually do. Since 2022 NoName057(16) has claimed more than 1,500 DDoS attacks against NATO-aligned states, per CSIS, including strikes on Swedish banks, more than 250 German companies and institutions, and infrastructure connected to the June 2025 NATO summit in The Hague.
Al Jazeera reported the group ran a Telegram-based volunteer army of over 4,000 recruits paid in cryptocurrency and gamified through leader boards.
But 2024-2025 marked a shift from nuisance to operational-technology sabotage. Testimony before the House Science Committee by Idaho National Laboratory's Virginia Wright, published on Congress.gov, confirmed that in January 2024 CARR "compromised industrial control systems at water utilities in Abernathy, Muleshoe, and Hale Center, Texas," causing tank overflows and losing tens of thousands of gallons. A parallel statement from witness Michael Tisdale, also on
Congress.gov, called Muleshoe "what disruption looks like": visible, deliberate, aimed at rural communities of fewer than 5,500 residents to send a message to their neighbours. In April 2025, according to the
SWP Berlin analysis, Z-Pentest breached the Lake Risevatnet dam in Norway and "managed to open its water valve at full capacity for hours before the intrusion was detected." An academic paper on
arXiv describes this trajectory as "escalatory hacktivism" — from protest to power plant — and argues it now blurs the line between activism, cybercrime and state-sponsored operations.
The July 2025 Operation Eastwood — the multilateral takedown that produced the first Spanish arrest — dismantled more than 100 servers across 19 jurisdictions and issued seven arrest warrants, including six by Germany. Yet as CSIS noted at the time, "this success is likely to be temporary — one round in an ongoing match." An empirical study of prior DDoS-for-hire takedowns published on
arXiv reinforces the pessimism: over half of booter sites seized in the FBI-led December 2022 wave returned within a median of one day, and the second wave's suppression of global DDoS volume was "minimal," with the market recovering within roughly six weeks. Arrests of facilitators like the Palencia suspect, prosecuted as terrorism collaborators with asset freezes attached, are the response to that resilience — not takedowns of code, but takedowns of the humans behind wallets.
Who benefits, who loses — and what Moscow watches
The clearest institutional beneficiary is Europol's European Cybercrime Centre and its Joint Cybercrime Action Taskforce (J-CAT), which houses cyber liaison officers from 13 EU member states and 7 non-EU partners including the United States. CSIS argues J-CAT is the operational spine of Operation Eastwood and should be replicated with new partners in Japan, South Korea, Singapore and Kenya. On the US side, an academic co-authorship analysis of joint cybersecurity advisories on
arXiv finds a "tightly knit U.S. triad — CISA, FBI, and NSA — densely connected with Five Eyes and select European allies," with CISA and the FBI functioning as coordination hubs and Australia's ASD-ACSC and the UK's NCSC acting as bridge nodes. The Palencia case, tipped by the FBI's Los Angeles field office and executed by Spain's Policía Nacional, is that network in operational form.
The clear losers are the mid-tier operatives: the couriers, wallet-holders, and Telegram admins who assumed hacktivist branding gave them plausible deniability. Once a Western judiciary accepts CARR and NoName057(16) as extensions of the Russian state, the entire volunteer scaffold Europol described — 4,000 gamified DDoSia contributors, per Al Jazeera — becomes prosecutable under terrorism and destabilisation statutes rather than lesser cybercrime laws. The Justice Department's December 2025 indictment of Ukrainian national Victoria Dubranova, referenced in the
CyberScoop report and followed by her extradition and guilty plea in two federal cases, is the US-side template.
The Kremlin's calculus shifts too. So long as CARR and NoName057(16) provided plausible deniability, they gave Russia a low-cost harassment capability against Ukraine's supporters. Once European judges rule these groups are effectively GRU proxies (the Atlantic Council's May 2025 study Confronting Russia's Cyber Power argues the "multidirectional, murky, and dynamic nature of Russia's cyber ecosystem" is itself the point), every future DDoS strike can be attributed politically to Moscow with judicial cover, not just diplomatic protest. That raises the escalation cost of Russian hybrid operations, particularly against NATO-adjacent utilities.
Diplomat View
The Palencia arrest looks like a footnote to Operation Eastwood. It is not. It is the first European deployment of terrorism law against a Russian hacktivist facilitator, and it establishes a doctrinal template every EU member with comparable statutes can copy. The forecast: expect at least three more European jurisdictions to bring terrorism-adjacent charges against CARR or NoName057(16)-linked defendants within twelve months, and expect the next wave of Council listings under Regulation 2024/2642 to explicitly cite the December 2025 joint advisory as attribution evidence. Two developments would revise this call: a European court rejecting the terrorism classification on appeal, or a Russia-Ukraine ceasefire deal that formally deprioritises hybrid-threat sanctions. Neither is likely on current trajectories. The larger consequence is jurisprudential: once "hacktivist" no longer functions as a legal shield, Moscow's proxy model — the very ambiguity the Atlantic Council warned about — degrades as a strategic asset.
What to watch next
- Spanish charging document: The Audiencia Nacional's decision on whether to certify the terrorism-collaboration count against the Palencia suspect will be the first judicial test of the classification. A ruling is expected in the coming months.
- Next EU sanctions wave: The Council's July 2026 review of Decision (CFSP) 2024/2643 is the earliest opportunity to add named CARR and NoName057(16) operatives to the destabilisation list — building directly on the June 15, 2026 additions.
- US indictments: With the State Department offering up to $10 million for information on NoName057(16) leaders and up to $2 million on CARR figures, per
CyberScoop, watch for a second US superseding indictment tied to the Dubranova cooperation.
The Bottom Line
The bottom line: Spain has done something Washington cannot. It put a Russian hacktivist facilitator on a terrorism charge sheet inside the European Union and made that the template. If the Audiencia Nacional certifies it, "hacktivism" will cease to function as legal camouflage for Kremlin-aligned cyber operations across the bloc, and Moscow's proxy model will lose the ambiguity that made it strategically useful.
Discover more

US Politics
SNAP Food Assistance Faces Legal Challenges
In 2026, SNAP faces stricter eligibility rules and mounting legal challenges, threatening food assistance for the millions of Americans who rely on the program.

US Politics
House Ethics Committee Pushes Sexual Miscond.
The House Ethics Committee has shifted responsibility for sexual harassment settlement records to the Office of Congressional Workplace Rights, complicating disclosure efforts.
India
Rajnath Singh's Durga Squad for 2026 Polls
Rajnath Singh's Durga Squad promised women's safety in Bengal but has since disappeared from the agenda, revealing BJP's true priorities.

Conflict & Security
West Africa Food Crisis: Three Shocks in 2026
Conflict, climate extremes, and the Strait of Hormuz closure drive a severe food crisis in West and Central Africa, with fertilizer prices surging 80% and millions displaced.