A massive power outage affected Spain, Portugal, and parts of southwestern France, leaving tens of millions without electricity for hours due to cascading failures in the power generation and transmission systems. The incident, which was not caused by a cyberattack but by technical and operational failures, highlighted the fragility of interconnected European grids and raised concerns about the preparedness of critical infrastructure against both accidental and malicious disruptions. Experts noted that fragmented incident handling and lack of coordination among European operators exacerbate the risk of widespread outages, drawing parallels to past cyberattacks on power grids such as the 2015 Ukraine incident.
In response to increasing threats, industry analysts and regulators are urging grid operators to unify cybersecurity and physical security strategies. The convergence of operational technology (OT) and information technology (IT) has exposed critical infrastructure to a broader range of cyberthreats, including ransomware and malware, while physical attacks on grid assets have also surged in recent years. Surveys indicate that grid operators are equally concerned about cyber and physical risks, emphasizing the need for integrated security approaches to safeguard the reliability and resilience of power delivery systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Nearly a year after a major blackout in Spain, Red Eléctrica provided its system audio records to police as part of an Audiencia Nacional investigation examining whether the incident involved a cyberattack. The disclosure followed controversy over leaked recordings and disputes with power companies seeking judicial access to the materials.
Industry coverage described a growing effort to harden Europe’s electrical grids against cyberattacks and physical sabotage, emphasizing the convergence of cyber and physical security for grid operators. The references do not identify a single discrete triggering incident, patch, or official action beyond this broader security push.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
elmundo.es
Open sourcego.theregister.com
Open sourcedarkreading.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.