Menu
Browse

Cyber Incident Victim: City of Jerez de la Frontera

Date:

Oct 2019

Location:

Spain

Summary

A hacker compromised the computer system of the City of Jerez de la Frontera, demanding a bitcoin ransom to restore access and causing service outages on the municipal website. The southern Spanish city, home to approximately 212,000 residents, received assistance from national computer experts dispatched by Spain's interior ministry to resolve the attack. The municipality's mayor emphasized that services would only resume once full security was assured, though the specific ransom amount remained undisclosed. The incident highlights common criminal tactics leveraging cryptocurrency anonymity, despite broader advisories against paying ransoms due to potential long-term risks.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On the night of Tuesday, October 1, 2019, a cyber attacker compromised the computer systems of Jerez de la Frontera, a southern Spanish city with approximately 212,000 residents. The intrusion caused widespread outages affecting municipal online services accessible through the city's website, disrupting public operations. By Friday, October 4, city officials confirmed the attacker had seized control of the system and issued a ransom demand payable exclusively in bitcoin cryptocurrency to restore access. Municipal authorities did not disclose the specific ransom amount but emphasized the hacker’s insistence on bitcoin due to its perceived anonymity advantages for criminal transactions. The attack persisted for multiple days, with services remaining offline as technicians worked to contain the breach.

Cyber Incident Image

In response to the crisis, Spain’s Interior Ministry deployed three cybersecurity experts to assist local authorities in resolving the incident. Mayor Mamen Sánchez, leading the Socialist administration, publicly committed to restoring the municipal website only after achieving full security assurances, stating it would return when "100 percent secure." While the city’s statement acknowledged the severity of the attack on its sherry-producing community, it provided no details about whether ransom negotiations occurred or any funds were paid. The incident reflected broader patterns of ransomware attacks where criminals exploit cryptocurrencies’ anonymity, despite law enforcement agencies and security professionals routinely advising against capitulating to such demands due to ethical and practical risks. Many organizations nevertheless consider payment when facing costly system reconstruction scenarios.

Sources
Sources available to members
1 source