On November 5, 2025, Spanish radio station KISS FM appeared on the leak site of the rhysida ransomware group. The station, owned by Mediaset España and broadcasting both over traditional airwaves and online, is claimed to have had internal files exfiltrated during a ransomware attack. Public reporting indicates the number of people whose information was exposed remains unknown.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Kiss Fm
Get alerted the next time Kiss Fm files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Kiss Fm’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Available reporting describes the incident as a ransomware deployment that resulted in the theft of internal documents. The data was later published on the group’s leak site, a common tactic used to pressure victims. KISS FM has not released a detailed public statement on the exact volume or type of records involved, but the presence of the company name on the rhysida portal confirms exfiltration occurred. No specific deadline for ransom payment has been publicly tied to this listing.
Why This Matters for You and Your Family
When a media company like KISS FM suffers a breach, the information stolen can include employee records, listener contest entries, marketing databases, or vendor contracts that contain personal details. If your name, email, phone number, or address appears in any of those files, it can surface in unexpected places. For ordinary families this often means sudden spam, phishing emails pretending to be from the station, or more targeted scams that reference your past interactions with the broadcaster. Children who entered contests or used family email addresses for station apps or events can also find their information exposed, increasing risks of identity misuse that parents must later untangle.
The Doxxing and Identity-Chain Implications
Leaked internal files frequently contain more than one piece of information about a person. An email address paired with a phone number or date of birth becomes a starting point for attackers to link gaming usernames, social-media handles, and family relationships. These connections can cascade into full doxxing chains where one breach exposes accounts across multiple services. Credential leaks of this nature have repeatedly led to gaming account takeovers, especially for children whose usernames and passwords are sometimes stored in shared family documents or contest spreadsheets. Once initial access is gained, attackers use the foothold to harvest further data and sell or publish it.