CSIDB logo
Incident

Ayuntamiento de Sant Antoni de Portmany

Incident posture

Attack window
Jan 2024
Location
Spain
Status
Historical
CIA posture
Available to members
Updated
2026-01-26 11:04

Linked entities

Victim
Ayuntamiento de Sant Antoni de Portmany
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jan 2024
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Ayuntamiento de Sant Antoni de Portmany experienced a Lockbit 3.0 ransomware attack that encrypted municipal systems, prompting an immediate crisis response. A coordinated effort involved forensic analysis, mass credential resets, revocation of electronic certificates, implementation of multi-factor authentication, system updates, enhanced network filtering, and 24/7 monitoring. Recovery prioritized cloud-based services, restoring 90% of workstations, reconnecting internal networks and SARA administrative systems, with most public services expected to resume shortly. Security measures were strengthened throughout the restoration process while forensic investigations continued.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On January 31, 2024, municipal information systems of the Ayuntamiento de Sant Antoni de Portmany suffered a cyberattack identified as Lockbit 3.0 ransomware, which encrypted municipal files. The attack was detected on the same day, prompting immediate activation of a Crisis Committee to coordinate response efforts across technical and administrative teams. The committee prioritized restoring services with enhanced security protocols while conducting a forensic analysis to determine the full scope of the compromise. Initial technical measures included a comprehensive review of all municipal workstations, mass credential resets for internal and external accounts, and revocation of electronic certificates to prevent identity spoofing. The municipality implemented mandatory multi-factor authentication for all service access points, updated affected systems, and enforced stricter internet browsing filters alongside a 24x7 monitoring service with advanced threat prevention capabilities.

Recovery operations shifted to cloud-based infrastructure to accelerate service restoration with improved security safeguards. As of the latest update, 90% of municipal workstations had been inspected and returned to employee use, with inter-office network connections and access to the SARA (Sistemas de Aplicaciones y Redes para las Administraciones) network fully reinstated. The municipality anticipates restoring most citizen-facing services within one week of the incident report date but continues to refine its response pending completion of the forensic investigation. No data exfiltration or operational timelines beyond service restoration were disclosed. Administrative communications emphasized procedural transparency through incremental updates until full system recovery and analysis conclude.

Sources

Sources available to members: 1 source.

CSIDB