Lyce · Hybrid Watch

hw_cedf8a6443a3d3f1

Massive multi-sector DDoS campaign hits Spain, attributed to the pro-Russian hacktivist group NoName057(16).

Radware’s threat advisory reports that starting on 19 July 2023 (just days before the Spanish general election), NoName057(16) launched a two‐week “weeklong campaign” of 85 DDoS attacks across Spain. The targeted sites included the Spanish electoral authority (Junta Electoral Central), national statistics office (INE), public transport ticketing systems, bank portals, telecom/mobile service pages and major newspaper websites — a broad sweep of state, commercial and civic infrastructure. T The dynamics illustrate how the attackers used volume, timing (coinciding with national elections) and multi-domain targeting to impose cost, force allocation of defensive resources and generate uncertainty and disruption rather than seek immediate violent outcomes. Although websites were knocked offline temporarily, no physical infrastructure destruction was reported; yet the broad scope and high-impact nature elevate this incident firmly into the hybrid-warfare domain. Spain’s disclosure of the campaign and linking it to a Russian-linked hacking group underlines how Western European states are increasingly targets of non-kinetic operations tied to the Russian Federation’s strategic posture.

Occurrence
2023-07-19
Publication
2023-07-18T22:00:00Z
First observed
2026-09-24T06:09:10.079Z
Review status
Not assessed
Countries
ES
Updated
2026-09-27T23:56:59.668Z

E/M/R/S scores

  • EExistence0/4 · Not assessed
  • MIntent0/4 · Not assessed
  • RRussian actor link0/4 · Not assessed
  • SRussian state responsibility0/4 · Not assessed

Facts

No facts

Sources

  1. Role
    discovery_lead
    Date
    2023-07-18T22:00:00Z

    Radware’s threat advisory reports that starting on 19 July 2023 (just days before the Spanish general election), NoName057(16) launched a two‐week “weeklong campaign” of 85 DDoS attacks across Spain. The targeted sites included the Spanish electoral authority (Junta Electoral Central), national statistics office (INE), public transport ticketing systems, bank portals, telecom/mobile service pages and major newspaper websites — a broad sweep of state, commercial and civic infrastructure. T The dynamics illustrate how the attackers used volume, timing (coinciding with national elections) and multi-domain targeting to impose cost, force allocation of defensive resources and generate uncertainty and disruption rather than seek immediate violent outcomes. Although websites were knocked offline temporarily, no physical infrastructure destruction was reported; yet the broad scope and high-impact nature elevate this incident firmly into the hybrid-warfare domain. Spain’s disclosure of the campaign and linking it to a Russian-linked hacking group underlines how Western European states are increasingly targets of non-kinetic operations tied to the Russian Federation’s strategic posture.