A ransomware attack hit Spain’s Port of Vigo, disrupting cargo traffic management systems and other digital services while forcing authorities to disconnect affected parts of the network. Port officials said some equipment was locked and the attackers sought a ransom payment, prompting cybersecurity teams to keep systems offline until they can verify the environment is secure. Investigators are still working to determine the initial access vector and whether any sensitive data was compromised.
Physical port activity, including ship movements and cargo handling, continued, but logistics coordination through digital platforms was impaired and some cargo-related processes were shifted to manual operations. Port president Carlos Botana said there is no timeline for full restoration, underscoring the operational risk ransomware poses to ports and other maritime organizations that support critical trade flows.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
Port president Carlos Botana said affected systems would remain offline until security teams were confident the network was safe. Authorities also began investigating the initial access vector and whether any sensitive data had been compromised.
After detecting the attack early Tuesday, authorities disconnected affected parts of the network to contain the incident. Some cargo-related and logistics coordination processes were moved to manual operations, while physical port activity continued.
A ransomware attack disrupted digital systems at Spain's Port of Vigo, affecting servers used for cargo traffic management and other digital services. Officials said some equipment was locked and that the attackers sought payment of a ransom.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.