A security breach at Puig de les Basses prison allowed inmates to access confidential files. Authorities confirm no critical systems were compromised. The incident has triggered a full investigation and new security measures.
Authorities in Catalonia are investigating a significant security breach at the Puig de les Basses prison in Figueres (Alt Empordà), after inmates managed to access confidential documentation stored on the facility’s internal network. The Department of Justice and Quality Democracy confirmed that the unauthorized access was detected recently, though the exact timing of the incident has not been disclosed. The breach, which involved two inmates, did not compromise critical penitentiary systems or disrupt the prison’s operations, according to official statements.
The incident came to light when prison staff noticed irregular activity on the network, prompting immediate activation of security protocols. The Agència de Ciberseguretat de Catalunya was called in to conduct a thorough technical analysis, aiming to determine the scope of the breach and how the inmates exploited the system. Early findings indicate that the individuals responsible have already been identified and that the breach was limited to shared documentation on network drives, not affecting sensitive personal data or the core prison management systems.
Justice officials have reported the case to the Figueres duty court and notified the Catalan Data Protection Authority. The Mossos d’Esquadra’s cybercrime unit is also involved in the ongoing investigation. The two inmates implicated are not serving sentences for cyber-related offenses. According to sources cited by EL PAÍS, the breach was detected on Sunday afternoon, with the inmates allegedly using recently installed touchscreen terminals—intended for video calls and other services—to gain access to the network.
In response, the prison system across Catalonia is reinforcing digital security measures to prevent similar incidents. On Wednesday morning, Domingo Estepa, Director General of Penitentiary Affairs, held an extraordinary meeting with union representatives to inform them of the breach and outline the steps being taken. The UGT union has demanded full transparency for all prison staff, a guarantee that no personal data of employees was accessed, and a comprehensive investigation into the extent of the breach and accountability for those involved.
Puig de les Basses currently houses around 900 inmates, exceeding the ideal capacity of 750. The incident highlights ongoing challenges in managing digital infrastructure within correctional facilities, especially as new technologies are introduced. Similar concerns about the vulnerability of institutional systems have been raised in other contexts, such as the recent exposure of weaknesses in Spain’s migrant protection network, as detailed in a report on the dismantling of a trafficking network in the Canary Islands.
Spain’s prison system has increasingly relied on digital tools for communication and administration, making cybersecurity a growing priority. The swift response by Catalan authorities in this case underscores the importance of robust protocols and ongoing vigilance as digitalization expands within public institutions.