On March 17, 2025, the Real Academia Española (rae.es) appeared on the leak site of the fog ransomware group. The attackers posted a sample of what they claim is internal files exfiltrated during a ransomware incident, with the total volume listed as under 1 GB. While the exact number of individuals whose personal information may have been exposed remains unknown, anyone who has corresponded with the institution, submitted documents, or had their details stored in its administrative systems could be affected.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch RAE (Real Academia Española) (rae.es)
Get alerted the next time RAE (Real Academia Española) (rae.es) files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about RAE (Real Academia Española) (rae.es)’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting based on the fog leak site indicates that the Spanish royal language academy suffered a ransomware intrusion in which attackers encrypted systems and exfiltrated a modest but sensitive cache of internal documents. The sample published on March 17 includes file listings that suggest the data contains administrative records rather than a massive trove of customer databases. No evidence has surfaced showing that credit card numbers or medical records were taken, yet the files could still hold names, contact details, correspondence, and other personally identifiable information typical of a national cultural institution.
The fog group set its usual extortion timeline, giving the organization a short window to negotiate before broader publication. As of the posting date, the full archive had not been released to the public, but the initial upload serves as proof that data left the RAE’s network.
Why This Matters for You and Your Family
Even a relatively small breach at a respected public institution can ripple into your daily life. If you or any member of your family has ever registered for courses, requested certifications, submitted manuscripts, or simply emailed the academy, your name, email address, postal address, or phone number may now sit in files controlled by criminals. Once that information is out, it can be sold, traded, or used to build profiles that make identity theft or targeted scams easier.