Lyce · Hybrid Watch

hw_9ac498b4671304fe

Pro-Russian hackers claim cyberattack on the website of a Spanish defence-industry firm servicing tanks for Ukraine.

A pro-Russian hacker group publicly claimed responsibility for a distributed-denial-of-service (DDoS) attack against Santa Bárbara Systems’ website, stating the target was Spain’s participation in the Ukraine crisis via tank refurbishment. The attack did not reportedly interrupt physical production but rendered the company’s web portal unavailable for a period, affecting communications and signalling vulnerability in the defence supply-chain. The attack struck within Spain’s domestic industrial base rather than a border or maritime zone, illustrating how hybrid threats penetrate allied states’ internal military-industry networks. The dynamics reflect how Russian-linked actors use cyber tools not only against governmental or civilian infrastructure but also defence-industry firms providing support to Ukraine, thereby striking at the adversary’s military-logistic chain. While no sabotage of physical equipment was publicly reported, the targeting of an arms-industry actor elevates the operation into the hybrid-warfare domain. Spain’s acknowledgement of the attack and its link to Russian-style hacktivists underscores the strategic risk faced by EU/NATO member states even when physically distant from the frontline.

Occurrence
2024-06-05
Publication
2024-06-04T22:00:00Z
First observed
2026-09-24T06:09:10.079Z
Review status
Not assessed
Countries
ES
Updated
2026-09-27T23:56:59.668Z

E/M/R/S scores

  • EExistence0/4 · Not assessed
  • MIntent0/4 · Not assessed
  • RRussian actor link0/4 · Not assessed
  • SRussian state responsibility0/4 · Not assessed

Facts

No facts

Sources

  1. Role
    discovery_lead
    Date
    2024-06-04T22:00:00Z

    A pro-Russian hacker group publicly claimed responsibility for a distributed-denial-of-service (DDoS) attack against Santa Bárbara Systems’ website, stating the target was Spain’s participation in the Ukraine crisis via tank refurbishment. The attack did not reportedly interrupt physical production but rendered the company’s web portal unavailable for a period, affecting communications and signalling vulnerability in the defence supply-chain. The attack struck within Spain’s domestic industrial base rather than a border or maritime zone, illustrating how hybrid threats penetrate allied states’ internal military-industry networks. The dynamics reflect how Russian-linked actors use cyber tools not only against governmental or civilian infrastructure but also defence-industry firms providing support to Ukraine, thereby striking at the adversary’s military-logistic chain. While no sabotage of physical equipment was publicly reported, the targeting of an arms-industry actor elevates the operation into the hybrid-warfare domain. Spain’s acknowledgement of the attack and its link to Russian-style hacktivists underscores the strategic risk faced by EU/NATO member states even when physically distant from the frontline.