CSIDB logo
Incident

Ayuntamiento de Villajoyosa

Incident posture

Attack window
Jul 2025
Location
Spain
Status
Unknown
CIA posture
Available to members
Updated
2026-07-18 07:13

Linked entities

Victim
Ayuntamiento de Villajoyosa
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Jul 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

El Ayuntamiento de Villajoyosa sufrió un ataque de ransomware que dejó inoperativos servicios básicos tras detectarse actividad anómala en sus sistemas informáticos. El consistorio está colaborando con el Centro de Operación de Ciberseguridad para recomponer los sistemas y recuperar la actividad, mientras mantiene los servicios operando de forma manual hasta que sea seguro volver a usar la infraestructura. Se están evaluando el impacto y analizando las causas para ordenar los pasos necesarios y retornar a la normalidad lo antes posible.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On the day before the announcement, municipal IT systems showed anomalous activity that triggered an internal alert. The following day, officials confirmed that the anomaly was a ransomware attack that had rendered basic municipal services inoperable. The disruption affected essential functions that rely on the computerized infrastructure, though the articles do not specify which services were impacted. The confirmation came after further analysis by the municipal technical team.

In response, the Ayuntamiento de Villajoyosa began collaborating with the Centro de Operación de Ciberseguridad (COCS) to recompose the affected systems and restore normal operations. To keep municipal activities from stopping, the council enabled parallel manual procedures while the computerized systems remained unsafe to use. Pedro Ramis, the councilor for Information Technology, emphasized that all administrative work would continue manually until the systems could be verified as secure. The manual workflow was implemented immediately after the ransomware was identified.

The COCS, which depends on the Centro Criptográfico Nacional, is tasked with assessing the full impact of the attack, analyzing its underlying causes, and defining the ordered steps required to return to normality as quickly as possible. These efforts include verifying the integrity of restored systems and ensuring that no residual threat remains before reconnecting them to the municipal network. The Ayuntamiento has stated that it will resume normal computerized operations only after receiving clearance from the cybersecurity team. The ongoing coordination aims to minimize downtime while maintaining service continuity through the temporary manual arrangements.

Sources

Sources available to members: 2 sources.

CSIDB