Lyce · Hybrid Watch

hw_feaa174f9e924d08

A coordinated distributed-denial-of-service (DDoS) campaign hit multiple Spanish government and municipal websites, with the pro-Russian hacktivist collective NoName057(16) claiming responsibility.

The hacktivist group claimed that more than ten Spanish municipal and regional portals were subjected to HTTP/HTTPS flood attacks, utilising bot-nets of compromised IoT devices and servers that reportedly generated over 2.3 Tbps of malicious traffic. The targets spanned across multiple autonomous communities, including Basque Country, Aragon, Castile-La Mancha and Catalonia, indicating that Spain’s institutional networks — not just national, but local civic infrastructure — were under digital assault. The campaign struck well inside Spanish administrative and service infrastructure rather than only at border regions or strategic maritime approaches. The dynamics of the attack reflect hybrid-warfare logic: the group singled out Spain’s support for Ukraine, timed its campaign to cause maximum administrative disruption across multiple sectors, and leveraged scalable digital disruption to force defensive resource allocation. Although no physical damage to infrastructure was reported publicly, the sheer volume of traffic and breadth of targets — including municipal services and transport systems — illustrate an escalation of hybrid-warfare activities beyond mere espionage. Spanish cybersecurity authorities responded with heightened alerts and mitigation, yet the incident demonstrated the vulnerability of local government digital portals which are essential for civic functioning.

Occurrence
2025-03-05
Publication
2025-03-04T23:00:00Z
First observed
2026-09-24T06:09:10.079Z
Review status
Not assessed
Countries
ES
Updated
2026-09-27T23:56:59.668Z

E/M/R/S scores

  • EExistence0/4 · Not assessed
  • MIntent0/4 · Not assessed
  • RRussian actor link0/4 · Not assessed
  • SRussian state responsibility0/4 · Not assessed

Facts

No facts

Sources

  1. Role
    discovery_lead
    Date
    2025-03-04T23:00:00Z

    The hacktivist group claimed that more than ten Spanish municipal and regional portals were subjected to HTTP/HTTPS flood attacks, utilising bot-nets of compromised IoT devices and servers that reportedly generated over 2.3 Tbps of malicious traffic. The targets spanned across multiple autonomous communities, including Basque Country, Aragon, Castile-La Mancha and Catalonia, indicating that Spain’s institutional networks — not just national, but local civic infrastructure — were under digital assault. The campaign struck well inside Spanish administrative and service infrastructure rather than only at border regions or strategic maritime approaches. The dynamics of the attack reflect hybrid-warfare logic: the group singled out Spain’s support for Ukraine, timed its campaign to cause maximum administrative disruption across multiple sectors, and leveraged scalable digital disruption to force defensive resource allocation. Although no physical damage to infrastructure was reported publicly, the sheer volume of traffic and breadth of targets — including municipal services and transport systems — illustrate an escalation of hybrid-warfare activities beyond mere espionage. Spanish cybersecurity authorities responded with heightened alerts and mitigation, yet the incident demonstrated the vulnerability of local government digital portals which are essential for civic functioning.