Real Academia Española
Incident posture
Linked entities
- Victim
- Real Academia Española
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
A cybersecurity attack struck the IT infrastructure of the Real Academia Española on the night of the first Saturday in February, prompting immediate containment and mitigation efforts by the institution. Following the incident, which was reported to the appropriate authorities and filed with law enforcement agencies, the organization confirmed that its heritage assets and core tools remained safe and fully operational. While most external services resumed normal function shortly after the attack, only minor restoration work continued to bring a few specialized resources back online in the days following.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On the night of Saturday, February 1, 2025, the information technology infrastructures of the Real Academia Española (RAE) were struck by a cybersecurity attack, as confirmed by sources from the institution to Europa Press and initially reported by Escudo Digital. The attack targeted the RAE's computing systems, prompting an immediate response from the institution once the intrusion was identified. Following the detection of the incident, the RAE promptly notified the competent authorities and filed a formal complaint with the Spanish law enforcement agencies, known as the Fuerzas y Cuerpos de Seguridad del Estado. The institution characterized its subsequent actions as beginning "immediately," launching containment and mitigation efforts designed to limit the spread and impact of the compromise across its digital environment.
In the days following the attack, the RAE undertook a series of measures to stabilize its operations and restore affected services. Once these measures were implemented, the institution confirmed that its heritage assets—referred to as its patrimonio—remained "safe," and that the external services offered by the RAE were functioning with normality. The only ongoing technical work at the time of reporting related to restoring access to some of the institution's most specialized resources, with officials indicating that these were expected to become operational again in the following days. The RAE did not disclose specific technical details about the nature of the attack, the method of intrusion, or the identity of any potential threat actor involved in the incident. Similarly, no information was provided regarding whether any data was exfiltrated, encrypted, or otherwise affected as a result of the cyberattack.
The incident affected the RAE during a period of significant digital activity for the institution, which maintains extensive linguistic databases and online resources used by scholars and the general public. While the attack prompted temporary disruptions to certain specialized digital resources, the institution's core services and its broader heritage holdings remained protected and accessible. The RAE's decision to engage both regulatory authorities and law enforcement from the outset reflects a standard protocol for handling cybersecurity incidents of this nature, ensuring that appropriate governmental bodies were informed and that the event was formally documented for any subsequent investigation. The reporting from Europa Press on March 19, 2025, marked the public disclosure of the incident, more than six weeks after the initial attack occurred, suggesting that the institution took time to stabilize its systems and assess the full scope of the event before making it publicly known.
Sources
Sources available to members: 1 source.