Indra Group, a Spanish defence, aerospace and technology contractor and a member of NATO's cyber coalition, has confirmed a ransomware attack affecting one of its subsidiaries.
The Gentlemen ransomware gang has claimed responsibility and is threatening to leak data it says it stole from the affected subsidiary unless Indra pays. Indra has not detailed what data was accessed or confirmed the gang's claims about its scope, which is standard practice while an investigation is ongoing.
Defence contractors are attractive ransomware targets not just for the ransom itself, but for the sensitivity of what a leak could expose: contract details, personnel information, and potentially technical documentation. Attacks on companies with NATO ties also carry a geopolitical dimension that purely commercial ransomware incidents don't.
This one is mostly relevant if you work in or supply the defence sector, where it's a reminder that ransomware groups don't treat critical infrastructure or defence ties as off-limits. For general readers, there's no direct action here, but it's worth watching whether Gentlemen follows through on the leak threat, since defence-sector leaks tend to have knock-on effects for subcontractors too.