Spanish Tax Agency Leaks Bank and Crypto Data

Spain's tax authority sent files with third-party fiscal and banking data, calling it a minor glitch while exposing Bitcoin declarants.

English · Original discussion in Spanish · Published

Spanish Tax Agency Leaks Bank and Crypto Data
Tax Agency Sends Private Fiscal and Banking Data to Wrong Recipients

What happens when your tax records, bank accounts, and assets end up in a stranger's inbox? They stop being private. The Agencia Tributaria (Spanish Tax Agency) sent electronic communications to various taxpayers containing files with other people's information—including home addresses and bank account numbers—and the agency has dismissed this as a "minor" failure. The shipment was not received by its intended recipient. It was received by someone else.

It offers little comfort to know there was no external hack if the result is the same: fiscal and asset data are circulating among people who have no reason to possess them. Those who declared Bitcoin, gold, or any registered asset now face a new problem.

Was It a Hack or a Sending Error?

There was no digital break-in. It was a combination of poor correspondence handling: files containing third-party information were attached to electronic shipments. The file design itself made it difficult to read at a glance—continuous text without formatting—but opening it with an editor other than Notepad reveals the data neatly organized and perfectly legible. They were not encrypted. Just jumbled together.

The best analogy is analog. It’s like distributing photocopies of letters addressed to your neighbors because the word processor messed up the mail merge. It’s not a theft from the post office warehouse: the material came from inside, protected by a system that no one reviewed. And as one participant summarized, the criterion is simple: an IT failure is either serious or it isn’t, depending on the nature of what was revealed. A list of addresses and accounts is not a minor incident.

The Seville City Council Case: ID Number as Master Key

This state-level leak adds to another episode pointing to the same hole. In the Virtual Office of the Agencia Tributaria de Sevilla—the municipal body, not the national one—it was enough to enter any citizen's DNI (National Identity Document), without any other security check such as a digital certificate, to query their address, bank account number, and pending fines. No password. No second factor. A public identifier worked as the system key.

Here lies the paradox highlighted by many: the digital certificate, a tool that can sometimes be cumbersome for citizens to install, is precisely the barrier preventing anyone from querying anyone else's record. When replaced by the DNI, protection disappears.

Why Is Declared Bitcoin the Most Concerning Data?

Because a bank balance or salary slip is traceable, but Bitcoin has another quality: it identifies a specific holder and their wealth. Those who declared it to the tax agency are no longer anonymous. The data allows knowing who holds it, how much, and, with the address in the same package, where the owner lives. The same applies to gold: if declared, it is locatable, and a physical asset can be sought out.

The discussion quickly moved to the future. If such a failure occurs with current databases, what would happen when central bank digital currency is launched? The episode was read as a warning about the infrastructure that would safeguard that system, without a closed conclusion.

From 1977 to 1981: When Spanish Incomes Were Public

This has peine before, according to memories shared in the thread. Between 1977 and 1978, income tax declarations for all Spaniards were public. In 1979 and 1980, the tax agency published the IRPF (Personal Income Tax) percentage paid by each citizen: with thirty brackets and nearly 70% at the maximum, the percentage identified quite well what each person earned. Very useful, in the view of one participant, for those wanting to choose targets for ransom negotiations.

Opacity was imposed after the kidnapping of Luis Suñer, owner of Helados Avidesa, in January 1980, carried out by ETA. Adolfo Suárez was governing then, in power between 1977 and 1982. Two versions circulated in the thread regarding the reason for the change: one blamed the PSOE (Spanish Socialist Workers' Party) for stopping the publication of data in 1981, and another recalled that the PSOE did not govern until 1982 and placed the return to opacity under UCD (Union of the Democratic Centre) trinc the kidnapping. Assets and income should be secret, this school of thought argues, and not just from curious neighbors.

Can You Sue the Tax Agency for the Leak?

The question remains open: can you claim damages from the tax agency for personal data protected by data protection laws? There was no definitive answer in the thread.

The repeated contrast is with the private sector, where a data breach is punished with severe fines. In the administration, participants saw not a single fine, dismissal, or resignation, summarizing it as total impunity. Meanwhile, the official narrative continues to try to downplay the scope: a minor failure, they say, when the package contained addresses and bank accounts of people who never authorized sharing them.

So if you declared Bitcoin, hold gold, or simply have an account with a balance, start checking your email. Perhaps the recipient of your banking record isn't you. But someone has it, and the address traveled in the same package.

Summary of a discussion on Burbuja.info - Foro de economía, actualidad y política., translated from Spanish and reviewed before publication. Read the full discussion (197 replies).

More summaries

All summaries in English →

Back