Cyber Incident Victim: Ayuntamiento de Villajoyosa
Date:
Jul 2025
Location:
Spain
Summary
El Ayuntamiento de Villajoyosa sufrió un ataque de ransomware que dejó inoperativos servicios básicos tras detectarse actividad anómala en sus sistemas informáticos. El consistorio está colaborando con el Centro de Operación de Ciberseguridad para recomponer los sistemas y recuperar la actividad, mientras mantiene los servicios operando de forma manual hasta que sea seguro volver a usar la infraestructura. Se están evaluando el impacto y analizando las causas para ordenar los pasos necesarios y retornar a la normalidad lo antes posible.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On the day before the announcement, municipal IT systems showed anomalous activity that triggered an internal alert. The following day, officials confirmed that the anomaly was a ransomware attack that had rendered basic municipal services inoperable. The disruption affected essential functions that rely on the computerized infrastructure, though the articles do not specify which services were impacted. The confirmation came after further analysis by the municipal technical team.

In response, the Ayuntamiento de Villajoyosa began collaborating with the Centro de Operación de Ciberseguridad (COCS) to recompose the affected systems and restore normal operations. To keep municipal activities from stopping, the council enabled parallel manual procedures while the computerized systems remained unsafe to use. Pedro Ramis, the councilor for Information Technology, emphasized that all administrative work would continue manually until the systems could be verified as secure. The manual workflow was implemented immediately after the ransomware was identified.
The COCS, which depends on the Centro Criptográfico Nacional, is tasked with assessing the full impact of the attack, analyzing its underlying causes, and defining the ordered steps required to return to normality as quickly as possible. These efforts include verifying the integrity of restored systems and ensuring that no residual threat remains before reconnecting them to the municipal network. The Ayuntamiento has stated that it will resume normal computerized operations only after receiving clearance from the cybersecurity team. The ongoing coordination aims to minimize downtime while maintaining service continuity through the temporary manual arrangements.
