Cyber Incident Victim: Spain
Date:
Jan 2023
Location:
Spain
Summary
A cyberattack of unknown origin targeted the Ayuntamiento de Durango, disrupting municipal operations. The incident occurred on a Sunday morning, prompting immediate notification to national authorities and cybersecurity experts. The municipality's IT department and external specialists are assessing impacts on system integrity and security, with significant disruptions reported to the Servicio de Atención a la CiudadanÃa and other services. Operations remain limited while recovery efforts continue to restore normal functionality.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On January 8, 2023, the Durango City Council in Spain experienced a cyberattack of unknown origin that disrupted municipal operations. The attack was detected on Sunday morning, prompting immediate notification to Spanish authorities and the National Cryptologic Center (CCN). Municipal IT personnel, assisted by external cybersecurity experts, initiated an assessment to determine the extent of compromise to system integrity and security. Preliminary analysis confirmed significant operational impacts, particularly affecting the Citizen Service Center (SAC), which suffered severe service degradation. Other unspecified municipal services also experienced disruptions, with officials warning residents that service availability might remain limited or altered during recovery efforts. No details regarding the attack vector, perpetrator identity, or data compromise were disclosed at this stage.

Response efforts focused on containment and damage assessment, with no restoration timeline provided. The municipality maintained transparency about ongoing operational challenges but did not specify whether critical infrastructure or citizen data was accessed. Coordination with national cybersecurity entities continued as technicians worked to restore normal operations. Service limitations persisted during the initial recovery phase, though the scope of affected systems beyond the SAC remained undefined. The incident marked a notable disruption to local governance capabilities, with recovery priorities centered on system integrity verification before full service restoration.
