hw_43eaa36dd2d32931
Major power outage hits the Iberian Peninsula, affecting both Spain and Portugal.
On the afternoon of 28 April, virtually all of mainland Spain and large parts of Portugal experienced a sudden and widespread power loss; Spanish grid operator Red Eléctrica de España described the event as “exceptional and totally extraordinary”. According to one media report, the outage disrupted hospitals running on backup power, halted metro services, switched off traffic lights, and froze nuclear-plant operations. Amid the blackout, two pro-Russian hacker groups, Dark Storm Team and NoName057(16), claimed responsibility – posting messages on social media boasting that they had “cut off electricity” in NATO countries. However, the Spanish government’s preliminary assessment, published 17 June 2025, formally ruled out a cyber-attack, attributing the incident instead to a sudden loss of 15 GW generation and consequent voltage instability. Legislators and analysts pointed out that regardless of cause, the event underlines how vulnerable critical infrastructure is to hybrid-warfare threats, including digital disruption and sabotage of power systems. The geographical scope – covering Western Europe and far from the Russia-Ukraine frontline – emphasises that allied states beyond the immediate theatre are exposed to this kind of threat. The dynamics show how adversaries can use denial-of-service or sabotage-style operations (or at least claim them) against critical civilian infrastructure, thereby imposing cost, generating uncertainty, and forcing allied states to respond in domains beyond conventional warfare. Although no definitive attribution to the Russian Federation has been affirmed by governments, the claimed involvement of Russian-aligned groups and the target set (electricity grids) bring the incident within the broader pattern of Russian-style hybrid operations.
E/M/R/S scores
- EExistence0/4 · Not assessed
- MIntent0/4 · Not assessed
- RRussian actor link0/4 · Not assessed
- SRussian state responsibility0/4 · Not assessed
Facts
No facts
Sources
-
- Role
- discovery_lead
- Date
- 2025-04-28T17:48:30Z
On the afternoon of 28 April, virtually all of mainland Spain and large parts of Portugal experienced a sudden and widespread power loss; Spanish grid operator Red Eléctrica de España described the event as “exceptional and totally extraordinary”. According to one media report, the outage disrupted hospitals running on backup power, halted metro services, switched off traffic lights, and froze nuclear-plant operations. Amid the blackout, two pro-Russian hacker groups, Dark Storm Team and NoName057(16), claimed responsibility – posting messages on social media boasting that they had “cut off electricity” in NATO countries. However, the Spanish government’s preliminary assessment, published 17 June 2025, formally ruled out a cyber-attack, attributing the incident instead to a sudden loss of 15 GW generation and consequent voltage instability. Legislators and analysts pointed out that regardless of cause, the event underlines how vulnerable critical infrastructure is to hybrid-warfare threats, including digital disruption and sabotage of power systems. The geographical scope – covering Western Europe and far from the Russia-Ukraine frontline – emphasises that allied states beyond the immediate theatre are exposed to this kind of threat. The dynamics show how adversaries can use denial-of-service or sabotage-style operations (or at least claim them) against critical civilian infrastructure, thereby imposing cost, generating uncertainty, and forcing allied states to respond in domains beyond conventional warfare. Although no definitive attribution to the Russian Federation has been affirmed by governments, the claimed involvement of Russian-aligned groups and the target set (electricity grids) bring the incident within the broader pattern of Russian-style hybrid operations.