CSIDB logo
Incident

City Council of Durango

Incident posture

Attack window
Jan 2023
Location
Spain
Status
Historical
CIA posture
Available to members
Updated
2026-07-15 02:03

Linked entities

Victim
City Council of Durango
Threat actors
2 actors
Sources
2 sources

Timeline

Occurred
Jan 2023
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The City Council of Durango suffered a severe cyberattack that paralyzed its computer systems and deactivated corporate email accounts, with recovery expected to take weeks. A ransom demand was issued, but officials refused payment while reporting the incident to data protection and cryptological authorities. Operational disruptions hindered citizens from submitting required documents by deadlines, prompting public complaints over unresolved deadline extensions despite the ongoing outage.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

The City Council of Durango in Biscay, Spain, experienced a severe cyberattack that began on or shortly before January 7, 2023, resulting in widespread operational disruption. Deputy Mayor Iker Urkiza publicly confirmed the attack had “completely paralyzed” municipal operations, with all council computers and corporate email accounts remaining deactivated since the weekend of January 7-8. The attack’s severity led officials to estimate system paralysis would persist for multiple weeks, indicating extensive compromise of critical infrastructure. Attackers delivered a ransom demand, though the city explicitly refused payment. Authorities reported the incident to the Basque Data Protection Agency and planned additional notification to Spain’s National Cryptological Center, reflecting compliance with national cybersecurity protocols. Technical containment measures were not detailed publicly, but the sustained deactivation of systems suggested ongoing forensic efforts and infrastructure rebuilding.

Citizens faced immediate practical consequences due to the prolonged outage, particularly regarding municipal deadlines for document submissions. Residents reported inability to file required paperwork through digital channels, generating complaints about the council’s failure to communicate deadline extensions despite the acknowledged service disruption. The paralysis hindered core administrative functions, though the specific mechanisms of the attack—whether ransomware, data exfiltration, or other malware—were not disclosed. No public statements addressed potential data compromise or provided restoration timelines beyond the “weeks” estimate. The incident remained under investigation by data protection authorities, with no attribution to specific threat actors disclosed in initial reports. Operational continuity challenges persisted as manual workarounds were not mentioned, leaving critical citizen services inaccessible through standard digital platforms.

Sources

Sources available to members: 2 sources.

CSIDB