Blackouts In Spain & Portugal Likely Caused By A Cyber Attack

A massive power outage struck the Iberian Peninsula on April 28, plunging millions of people into darkness as electricity supplies were suddenly cut across Spain and Portugal. According to Juanma Moreno, President of the Andalusian regional government, hostile activity by cyber criminals is  the most likely cause of the blackout. 

Portugal’s grid operator, RNA, offered an alternative explanation for the massive power outage when it It blamed a rare atmospheric phenomenon which caused "oscillations" and "vibrations" in high power lines, which in turn resulted in "synchronisation failures" across the national grid. 

It is unclear how such oscillations might have affected power supply across Spain.

Around midday on Monday electrical systems of all kinds started to break down across both nations, affecting electrical power, telecoms and internet connectivity affecting emergency services across both countries - only the offshore  islands were  unaffected. 

El Pais, the Spanish newspaper said, “the power outages have paralysed the normal operation of infrastructure, communications, roads, with widespread traffic light failures, train stations, airports, businesses, and buildings,” including incidents involving elevators. 

The Portuguese newspaper, Correio da Manha, said that police have been sent out into the streets to help with traffic control in the absence of the usual infrastructure to keep vehicles moving. Vodafone  blamed disruptions to its network across Portugal on the continuing electricity problems. Even he French Basque region neighbouring Spain is reported to have suffered “brief power cuts".

If this is the result of a cyber attack it will be the most significant attack of its kind since the 2015 and 2016 when widespread national blackouts were inflicted on Ukraine by Russian hackers, several years prior to the subsequent  failed invasion.  

While the exploit  affected hundreds of homes in western Ukraine, this incident is affecting millions of people across the Iberian Peninsula and an attack of such wide ranging impact affecting  major EU nations would be a challenging and complex operation, beyond the capabilities of all but the most skilled and well-resource nation-state  threat groups. 

The International Energy Agency recently warned that cyber attacks against utilities worldwide have more than doubled between 2020 and 2022 and while there have been some cases of undersea cables and even gas pipelines being severed in the past, these caused localised disruption, rather than affecting an entire nation. 

Most previous attacks on energy infrastructure, including those in Ukraine, Estonia  and the highly effective Stuxnet attack on nuclear facilities in Iran, have been blamed on nation state actors, although no nation has ever claimed responsibility.

@JuanMa_Moreno  |   El Pais |   CM Jornal  |   ITPro   |   Sky News   |   Figaro   |   Yahoo   |   BBC   | 

ITVX   |   Cybersecurity News   |   Ars Technica   |  IEA    

Image: 

You Might Also Read: 

Cybersecurity, Volt Typhoon & The Grid:


If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible




 

« Cybersecurity Risks In Legacy Scheduling Systems & How To Mitigate Them
Ransomware Attacks On The Energy Sector Surging »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

Infosecurity Europe, 3-5 June 2025, ExCel London

Infosecurity Europe, 3-5 June 2025, ExCel London

This year, Infosecurity Europe marks 30 years of bringing the global cybersecurity community together to further our joint mission of Building a Safer Cyber World.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

CERT-FR

CERT-FR

CERT-FR is the French national government computer security incident response team.

Center for Strategic Cyberspace & International Studies (CSCIS)

Center for Strategic Cyberspace & International Studies (CSCIS)

CSCIS seeks to advance global cyberspace security and prosperity by providing strategic insights for cyberspace and policy solutions to decision makers.

Kudelski Security

Kudelski Security

Kudelski Security is an international cybersecurity company providing innovative, independent and tailored security solutions for large enterprise and public sector clients.

Signifyd

Signifyd

Signifyd is the world's largest provider of Guaranteed e-Commerce Fraud Protection.

Cyber Resilient Energy Delivery Consortium (CREDC)

Cyber Resilient Energy Delivery Consortium (CREDC)

CREDC performs multidisciplinary R&D in support of the Energy Sector Control Systems Working Group’s Roadmap of resilient Energy Delivery Systems (EDS).

Center for Cyber Safety and Education

Center for Cyber Safety and Education

The Center for Cyber Safety and Education works to ensure that people across the globe have a positive and safe experience online through our educational programs, scholarships, and research.

American Cybersecurity Institute

American Cybersecurity Institute

American cybersecurity Institute is a newly formed not-for-profit organization dedicated to education, advocacy, study and analysis in the space of cybersecurity law and policy.

Authomize

Authomize

Authomize aggregates identities and authorization mechanisms from any applications around your hybrid environment into one unified platform so you can easily and rapidly manage and secure all users.

AirITSystems

AirITSystems

AirITSystems offer companies comprehensive IT security solutions that take all security considerations into account and are tailored to your business.

Rayzone Group

Rayzone Group

Rayzone Group offers a wide range of Cyber Security solutions and services, providing hollistic protection suitable for both enterprises and National cyber security centers.

Orro Group

Orro Group

Orro create 'future now' solutions that make it faster, simpler and safer for you to access, store and share information. Wherever, whenever and with whomever you want.

Software Improvement Group (SIG)

Software Improvement Group (SIG)

Software Improvement Group helps business and technology leaders drive their organizational objectives by fundamentally improving the health and security of their software applications.

Parablu

Parablu

Parablu is a leading provider of data security and resiliency solutions for the digital enterprise.

IS4IT Kritis

IS4IT Kritis

IS4IT is your partner for the successful planning, introduction and implementation of company-specific information security concepts.

Surf Security

Surf Security

SURF Security has transformed the browser into your strongest security asset while providing complete end-user privacy – all with full compliance.

RealmOne

RealmOne

RealmOne addresses the most challenging issues in the realms of defense and cyberspace, adapting to the continuously changing demands of our national security customers.